WinRAR Compressed File Size Misrepresentation Weakness
BID:8572
Info
WinRAR Compressed File Size Misrepresentation Weakness
| Bugtraq ID: | 8572 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 09 2003 12:00AM |
| Updated: | Sep 09 2003 12:00AM |
| Credit: | Discovery is credited to Bipin Gautam <[email protected]>. |
| Vulnerable: |
RARLAB WinRar 3.20 RARLAB WinRar 3.11 RARLAB WinRar 3.10 beta 5 RARLAB WinRar 3.10 beta 3 RARLAB WinRar 3.10 RARLAB WinRar 3.0 .0 RARLAB WinRar 2.90 RARLAB UnRar 2.71 |
| Not Vulnerable: |
RARLAB UnRar 3.2.3 |
Discussion
WinRAR Compressed File Size Misrepresentation Weakness
WinRAR is prone to a weakness that may allow malicious parties to misrepresent the size of compressed files. This issue occurs because WinRAR trusts values in the .rar header without adequately verifying the actual file size. This presents a security threat because a user may expect that a compressed file is a certain size and decompress it based on this assumption.
UnRar is also prone to this issue. The UnRar add-on is available for a number of operating systems, including Unix/Linux derivatives and may be invoked automatically by various virus scanners. This could pose an additional attack vector which does not require user interaction to exploit.
There have been conflicting reports as to whether WinRar 3.20 is vulnerable to this issue or not.
WinRAR is prone to a weakness that may allow malicious parties to misrepresent the size of compressed files. This issue occurs because WinRAR trusts values in the .rar header without adequately verifying the actual file size. This presents a security threat because a user may expect that a compressed file is a certain size and decompress it based on this assumption.
UnRar is also prone to this issue. The UnRar add-on is available for a number of operating systems, including Unix/Linux derivatives and may be invoked automatically by various virus scanners. This could pose an additional attack vector which does not require user interaction to exploit.
There have been conflicting reports as to whether WinRar 3.20 is vulnerable to this issue or not.
Exploit / POC
WinRAR Compressed File Size Misrepresentation Weakness
A proof-of-concept has been made available at the following location:
http://www.geocities.com/visitbipin/test123.zip
A proof-of-concept has been made available at the following location:
http://www.geocities.com/visitbipin/test123.zip
Solution / Fix
WinRAR Compressed File Size Misrepresentation Weakness
Solution:
This issue is addressed in UnRar 3.2.3. It is not known if WinRar fixes are available.
RARLAB UnRar 2.71
Solution:
This issue is addressed in UnRar 3.2.3. It is not known if WinRar fixes are available.
RARLAB UnRar 2.71
-
RARLAB unrarsrc-3.2.3.tar.gz
http://www.rarlab.com/rar/unrarsrc-3.2.3.tar.gz
References
WinRAR Compressed File Size Misrepresentation Weakness
References:
References:
- WinRAR Homepage (WinRAR)
- Winrar doesn't determine the actual size of compressedfiles+possibility of DoS (hUNTER 007
)