UUDeview MIME Archive Buffer Overrun Vulnerability
BID:9758
Info
UUDeview MIME Archive Buffer Overrun Vulnerability
| Bugtraq ID: | 9758 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0333 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2004 12:00AM |
| Updated: | Jul 12 2009 03:06AM |
| Credit: | This issue was announced by iDEFENSE. |
| Vulnerable: |
WinZip WinZip 8.1 SR-1 WinZip WinZip 8.1 WinZip WinZip 8.0 WinZip WinZip 7.0 UUDeview UUDeview 0.5.19 UUDeview UUDeview 0.5.18 OpenPKG OpenPKG Current Gentoo Linux 1.4 _rc3 Gentoo Linux 1.4 _rc2 Gentoo Linux 1.4 _rc1 Gentoo Linux 1.4 |
| Not Vulnerable: |
WinZip WinZip 9.0 UUDeview UUDeview 0.5.20 Convert-UUlib Convert-UUlib 1.0.1 Convert-UUlib Convert-UUlib 1.0 |
Discussion
UUDeview MIME Archive Buffer Overrun Vulnerability
A buffer overrun vulnerability has been reported in UUDeview. This issue exists in the MIME parsing routines.
It is reported that this issue may be exploited via a malicious MIME archive that specifies excessively long strings for various parameters. This could be exploited to execute arbitrary code on a system in the context of a user who opens a malicious MIME archive using the UUDeview program.
It should be noted that UUDeview is shipped as a component of WinZip.
A buffer overrun vulnerability has been reported in UUDeview. This issue exists in the MIME parsing routines.
It is reported that this issue may be exploited via a malicious MIME archive that specifies excessively long strings for various parameters. This could be exploited to execute arbitrary code on a system in the context of a user who opens a malicious MIME archive using the UUDeview program.
It should be noted that UUDeview is shipped as a component of WinZip.
Exploit / POC
UUDeview MIME Archive Buffer Overrun Vulnerability
The reporters of this vulnerability possess proof-of-concept exploit code that is not publicly available or known to be circulating in the wild.
The following exploit has been provided by snooq to leverage this issue against WinZip on Windows 2000 and XP with SP1:
The reporters of this vulnerability possess proof-of-concept exploit code that is not publicly available or known to be circulating in the wild.
The following exploit has been provided by snooq to leverage this issue against WinZip on Windows 2000 and XP with SP1:
Solution / Fix
UUDeview MIME Archive Buffer Overrun Vulnerability
Solution:
UUDeview has released an updated version to address this issue.
This issue has been addressed in WinZip 9.0. Users are strongly urged to upgrade.
Gentoo Linux have released an advisory (200403-05) and updates to address this issue. Gentoo users are advised to upgrade to UUDeview 0.5.20 by emerging the updated packages as follows:
# emerge sync
# emerge -pv ">=app-text/uudeview-0.5.20"
# emerge ">=app-text/uudeview-0.5.20"
OpenPKG have released a security advisory (OpenPKG-SA-2004.006) and fixes to address this issue. Please see referenced advisory for further details.
UUDeview UUDeview 0.5.18
UUDeview UUDeview 0.5.19
WinZip WinZip 7.0
WinZip WinZip 8.0
WinZip WinZip 8.1 SR-1
WinZip WinZip 8.1
Solution:
UUDeview has released an updated version to address this issue.
This issue has been addressed in WinZip 9.0. Users are strongly urged to upgrade.
Gentoo Linux have released an advisory (200403-05) and updates to address this issue. Gentoo users are advised to upgrade to UUDeview 0.5.20 by emerging the updated packages as follows:
# emerge sync
# emerge -pv ">=app-text/uudeview-0.5.20"
# emerge ">=app-text/uudeview-0.5.20"
OpenPKG have released a security advisory (OpenPKG-SA-2004.006) and fixes to address this issue. Please see referenced advisory for further details.
UUDeview UUDeview 0.5.18
-
OpenPKG uudeview-0.5.18-1.3.1.src.rpm
OpenPKG 1.3
ftp://ftp.openpkg.org/release/1.3/UPD/uudeview-0.5.18-1.3.1.src.rpm
UUDeview UUDeview 0.5.19
-
OpenPKG uudeview-0.5.19-2.0.1.src.rpm
OpenPKG 2.0
ftp://ftp.openpkg.org/release/2.0/UPD/uudeview-0.5.19-2.0.1.src.rpm -
UUDeview UUDeview 0.5.20 for Windows (Console)
http://www.fpx.de/fp/Software/UUDeview/download/uudeview-win32.zip -
UUDeview UUDeview 0.5pl20 for Unix
http://www.fpx.de/fp/Software/UUDeview/download/uudeview-0.5.20.tar.gz
WinZip WinZip 7.0
-
WinZip WinZip 9.0
http://www.winzip.com/downwzeval.htm
WinZip WinZip 8.0
-
WinZip WinZip 9.0
http://www.winzip.com/downwzeval.htm
WinZip WinZip 8.1 SR-1
-
WinZip WinZip 9.0
http://www.winzip.com/downwzeval.htm
WinZip WinZip 8.1
-
WinZip WinZip 9.0
http://www.winzip.com/downwzeval.htm
References
UUDeview MIME Archive Buffer Overrun Vulnerability
References:
References:
- UUDeview Home Page (UUDeview)
- WinZip Homepage (WinZip)
- WinZip MIME Parsing Buffer Overflow Vulnerability (iDEFENSE)