|
|||||||||||
|
X-Diesel Unreal Commander v0.92 (build 573) multiple vulnerabilities
From: Gynvael Coldwind <gynvael(at)vexillium.org>
Date: Thu Aug 23 2007 - 07:39:44 EDT
Name : X-Diesel Unreal Commander v0.92 (build 573) multiple
vulnerabilities
Threat level : HIGH Discovered : 2007-08-09 Published : 2007-08-23 Credit : Gynvael Coldwind Vulnerable : 0.92 (build 573), 0.92 (build 565), prior also may be affected
Unreal Commander is an award winning freeware file manager for Windows 98/ME/2000/XP/2003/Vista. The application support multiple archive formats, has a built-in ftp client, and other features. Unreal Commander fails to check user-supplied input while processing ZIP and RAR archives. A malformed ZIP or RAR file can be used to perform a directory traversal attack and place malware files in a location selected by the attacker. Successful exploitation can lead to a full compromitation of the system.
Something/../../../../../../Program Files/Something/ws2_32.dll If the user upacks such an archive, the Unreal Commander will create the file ws2_32.dll in the specified directory, instead of the directory where the user wants to extract it. This may lead to system compromitation, especially if the user executes Unreal Commander with admin privileges. PoC: http://blog.hispasec.com/lab/files/UnrealCommander_PoC_traversal.zip
2. ZIP name spoofing
PoC: http://blog.hispasec.com/lab/files/UnrealCommander_PoC_spoof.zip
3. ZIP file size heap information leak
4. RAR directory traversal
The vendor has been informed, but has not yet released a proper patch. The solution is to check if a RAR or ZIP file contains ".." in the names of the files in the archives. It is also advised not to run Unreal Commander with administrative privileges.
Permission is hereby granted to redistribute this advisory, providing that no changes are made and that the copyright notices and disclaimers remain intact. Copyright (C) 2007 Hispasec Sistemas. -- Gynvael Coldwind mailto: gynvael@vexillium.org mailto: michael@hispasec.comReceived on Thu Aug 23 12:18:11 2007 This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:13:16 EDT |
||||||||||
|
|||||||||||