Info-ZIP UnZip Encoded Character Hostile Destination Path Vulnerability

BID:7550

Info

Info-ZIP UnZip Encoded Character Hostile Destination Path Vulnerability

Bugtraq ID: 7550
Class: Access Validation Error
CVE: CVE-2003-0282
Remote: Yes
Local: No
Published: May 10 2003 12:00AM
Updated: Jul 11 2009 09:07PM
Credit: Discovery of this vulnerability credited to "jelmer" <[email protected]>.
Vulnerable: SCO OpenLinux Workstation 3.1.1
SCO OpenLinux Server 3.1.1
Info-ZIP UnZip 5.50
+ Debian Linux 3.0 sparc
+ Debian Linux 3.0 s/390
+ Debian Linux 3.0 ppc
+ Debian Linux 3.0 mipsel
+ Debian Linux 3.0 mips
+ Debian Linux 3.0 m68k
+ Debian Linux 3.0 ia-64
+ Debian Linux 3.0 ia-32
+ Debian Linux 3.0 hppa
+ Debian Linux 3.0 arm
+ Debian Linux 3.0 alpha
+ Debian Linux 3.0
+ MandrakeSoft Corporate Server 2.1
+ MandrakeSoft Multi Network Firewall 2.0
+ Mandriva Linux Mandrake 9.1 ppc
+ Mandriva Linux Mandrake 9.1
+ Mandriva Linux Mandrake 9.0
+ Mandriva Linux Mandrake 8.2 ppc
+ Mandriva Linux Mandrake 8.2
+ OpenPKG OpenPKG 1.2
+ OpenPKG OpenPKG 1.1
+ OpenPKG OpenPKG Current
+ Redhat Linux 7.2 ia64
+ Redhat Linux 7.2 i386
+ Redhat Linux 7.2 alpha
+ Redhat Linux 7.2
+ Redhat Linux 7.1 ia64
+ Redhat Linux 7.1 i386
+ Redhat Linux 7.1 alpha
+ Redhat Linux 7.1
+ Redhat Linux 7.0 sparc
+ Redhat Linux 7.0 i386
+ Redhat Linux 7.0 alpha
+ Redhat Linux 7.0
+ Redhat Linux 6.2 sparc
+ Redhat Linux 6.2 i386
+ Redhat Linux 6.2 alpha
+ Redhat Linux 6.2
+ Slackware Linux 9.0
+ Slackware Linux -current
+ Sun Linux 5.0.6
Not Vulnerable:

Discussion

Info-ZIP UnZip Encoded Character Hostile Destination Path Vulnerability

Info-ZIP UnZip contains a vulnerability during the handling of pathnames for archived files. Specifically, when certain encoded characters are inserted into '../' directory traversal sequences, the creator of the archive can cause the file to be extracted to arbitrary locations on the filesystem - including paths containing system binaries and other sensitive or confidential information.

This vulnerability was reported to affect Info-ZIP UnZip 5.50 and is similar to the vulnerability described in BID 5835.

Exploit / POC

Info-ZIP UnZip Encoded Character Hostile Destination Path Vulnerability

The following proof of concept was provided:

Solution / Fix

Info-ZIP UnZip Encoded Character Hostile Destination Path Vulnerability

Solution:
Debian have reported that fixes released in the original Debian advisory (DSA 344-1) may not have sufficiently addressed this issue. A revised advisory (DSA 344-2) has been released. Please see the referenced advisory for further details regarding obtaining and applying fixes.

Mandrake has released an updated advisory MDKSA-2003:073-1 with updated fixes to address this issue. See the attached advisory for further details. Users are advised to upgrade as soon as possible.

Conectiva has released a security advisory (CLA-2003:724) containing fixes to address this issue. Users are advised to upgrade as soon as possible.

Immunix has released a security advisory (IMNX-2003-7+-017-01) containing fixes to address this issue. Users are advised to upgrade as soon as possible.

RedHat fixes for this issue have been made available. See the attached advisory for further details.

Conectiva has released a security advisory (CLA-2003:672) containing fixes to address this issue. Users are advised to upgrade as soon as possible.

Mandrake has released advisory MDKSA-2003:073 with fixes to address this issue.

OpenPKG has released advisory OpenPKG-SA-2003.033 to address this issue.

Gentoo has released advisory 200307-02 to address this issue. Vulnerable users are advised to execute the following commands to update affected systems:

emerge sync
emerge unzip
emerge clean

Yellow Dog has released an advisory (YDU-20030710-1) to address this issue. Please see the attached advisory for details on obtaining and applying fixes.

Turbolinux has released an advisory (TLSA-2003-42.txt) to address this issue. Please see the attached advisory for details on obtaining and applying fixes.

Sun has released a fix for Sun Linux 5.0.6.

Sun has also released updated packages for Sun Cobalt Qube3, RaQ4, and RaQXTR.

SCO has released an advisory (CSSA-2003-031.0) for OpenLinux that addresses this issue.


SCO OpenLinux Workstation 3.1.1

SCO OpenLinux Server 3.1.1

Info-ZIP UnZip 5.50

References

Info-ZIP UnZip Encoded Character Hostile Destination Path Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report