Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Directory traversal and absolute path in multiple archivers

  rPSA-2007-0172-1 tar

  BitZipper Archive Extraction Directory traversal

  [SA19511] KGB Archiver Directory Traversal Vulnerability

  [SA19296] WinHKI Multiple Archive Directory Traversal Vulnerability

From:h e <het_ebadi_(at)_yahoo.com>
Date:10.04.2006
Subject:TUGZip Archive Extraction Directory traversal

TUGZip Archive Extraction Directory traversal
TUGZip is a powerful award-winning freeware archiving
utility for WindowsA® that provides support for a wide
range of compressed, encoded and disc-image files, as
well as many other very powerful features; all through
an easy to use application interface and Windows
Explorer integration.
Supports ZIP, 7-ZIP, A, ACE, ARC, ARJ, BH, BZ2, CAB,
CPIO, DEB, GCA, GZ, IMP, JAR, LHA (LZH), LIB, RAR,
RPM, SQX, TAR, TGZ, TBZ, TAZ, YZ1 and ZOO archives.
Create 7-ZIP, BH, BZ2, CAB, JAR, LHA (LZH), SQX, TAR,
TGZ, YZ1 and ZIP archives.

http://www.tugzip.com

Credit:
The information has been provided by Hamid Ebadi and
Claus Berghammer

( Hamid Network Security Team) : admin[at]hamid[.]ir
Claus Berghammer : office(at)cb-computerservice(dot)at

The original article can be found at :
http://hamid.ir/security

Vulnerable Systems:
TUGZip 3.4.0.0 , TUGZip 3.3.0.0 , TUGZip 3.1.0.2

Detail :

The vulnerability is caused due to an input validation
error when extracting files compressed with GZ (*.gz),
JAR(*.jar), RAR(*.rar), ZIP(*.zip) .
This makes it possible to have files extracted to
arbitrary locations outside the specified directory
using the "../" directory traversal sequence.


Do not extract untrusted  RAR and JAR and ZIP and GZ
files.
To reduce the risk, never extract files as an
administrative user.

harmless exploit:
use HEAP [Hamid Evil Archive Pack]
you can download it from Hamid Network Security Team :

http://www.hamid.ir/tools/


want to know more ?
http://www.hamid.ir/paper






__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around
http://mail.yahoo.com

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru
test server