Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[ GLSA 200502-32 ] UnAce: Buffer overflow and directory traversal vulnerabilities
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index News & Announcements
View previous topic :: View next topic  
Author Message
GLSA
Bodhisattva
Bodhisattva


Joined: 17 Apr 2002
Posts: 2602
Location: Raleigh, NC

PostPosted: Mon Feb 28, 2005 4:58 pm    Post subject: [ GLSA 200502-32 ] UnAce: Buffer overflow and directory trav Reply with quote

Gentoo Linux Security Advisory

Title: UnAce: Buffer overflow and directory traversal vulnerabilities (GLSA 200502-32)
Severity: normal
Exploitable: remote
Date: February 28, 2005
Updated: May 19, 2014
Bug(s): #81958
ID: 200502-32

Synopsis

UnAce is vulnerable to several buffer overflow and directory
traversal attacks.


Background

UnAce is an utility to extract, view and test the contents of an ACE
archive.


Affected Packages

Package: app-arch/unace
Vulnerable: <= 2.5-r3
Unaffected: >= 2.5-r3
Architectures: All supported architectures


Description

Ulf Harnhammar discovered that UnAce suffers from buffer overflows when
testing, unpacking or listing specially crafted ACE archives
(CAN-2005-0160). He also found out that UnAce is vulnerable to directory
traversal attacks, if an archive contains “./..” sequences or
absolute filenames (CAN-2005-0161).


Impact

An attacker could exploit the buffer overflows to execute malicious code
or the directory traversals to overwrite arbitrary files.


Workaround

There is no known workaround at this time.

Resolution

All UnAce users should upgrade to the latest available version:
Code:
# emerge --sync
      # emerge --ask --oneshot --verbose ">=app-arch/unace-2.5-r3"
   


References


CAN-2005-0160


CAN-2005-0161


Last edited by GLSA on Mon May 19, 2014 4:19 am; edited 4 times in total
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index News & Announcements All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum