Gamespy Arcade GSAPAK.EXE .APK Extraction File Corruption Vulnerability
BID:8309
Info
Gamespy Arcade GSAPAK.EXE .APK Extraction File Corruption Vulnerability
| Bugtraq ID: | 8309 |
| Class: | Design Error |
| CVE: |
CVE-2003-0650 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 26 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | The discovery of this vulnerability has been credited to Mike Kristovich <[email protected]>. |
| Vulnerable: |
GameSpy Arcade |
| Not Vulnerable: | |
Discussion
Gamespy Arcade GSAPAK.EXE .APK Extraction File Corruption Vulnerability
A vulnerability has been discovered in Gamespy Arcade. The occurs within the GSAPAK.EXE component which is designed to handle files using the .APK extension. These files are simply a compressed ZIP archive, however GSAPAK.EXE fails to sufficiently verify the integrity of files included within the archive. As a result, an attacker may be capable of including a file, containing directory traversal sequences (../) within it's name, which when extracted would overwrite an arbitrary system file. This file corruption would occur within the privilege context of the user recieving the .APK file.
A vulnerability has been discovered in Gamespy Arcade. The occurs within the GSAPAK.EXE component which is designed to handle files using the .APK extension. These files are simply a compressed ZIP archive, however GSAPAK.EXE fails to sufficiently verify the integrity of files included within the archive. As a result, an attacker may be capable of including a file, containing directory traversal sequences (../) within it's name, which when extracted would overwrite an arbitrary system file. This file corruption would occur within the privilege context of the user recieving the .APK file.
Exploit / POC
Gamespy Arcade GSAPAK.EXE .APK Extraction File Corruption Vulnerability
This vulnerability can be exploited by placing a malicious executable, containing a file name including directory traversal sequences (../), within a ZIP archive. The archive must then be modified to contain a .APK file extension.
This vulnerability can be exploited by placing a malicious executable, containing a file name including directory traversal sequences (../), within a ZIP archive. The archive must then be modified to contain a .APK file extension.
Solution / Fix
Gamespy Arcade GSAPAK.EXE .APK Extraction File Corruption Vulnerability
Solution:
It has been reported that a patch to address this issue is currently being developed and is scheduled for release in the near future. However, this information has not been confirmed by Symantec.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that a patch to address this issue is currently being developed and is scheduled for release in the near future. However, this information has not been confirmed by Symantec.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Gamespy Arcade GSAPAK.EXE .APK Extraction File Corruption Vulnerability
References:
References:
- GameSpy Arcade (GameSpy)
- GameSpy Arcade Arbitrary File Writing Vulnerability (Mike Kristovich
)