avatar

Please consider registering
guest

Log In Register

Semisecure Login is not enabled!
Please enable JavaScript and use a modern browser to ensure that your password is encrypted.

Register | Lost password?
Advanced Search:

— Forum Scope —



— Match —



— Forum Options —




Wildcard usage:
*  matches any number of characters    %  matches exactly one character

Minimum search word length is 4 characters - maximum search word length is 84 characters

Topic RSS
CORELAN-10-026 – TweakFS Zip Utility Version 1.0 Stack BOF
April 20, 2010
9:56
avatar
TecR0c
Australia

Special guest
Forum Posts: 56
Member Since:
January 22, 2010
Offline

Advisory        : CORELAN-10-026

Disclosure date : April 19th, 2010

CVECVE-2010-1458

http://www.corelan.be:8800/adv…..LAN-10-026

 

 

00 : Vulnerability information

 Product : TweakFS Zip Utility

 Version : 1.0 (latest version)

 Vendor : TweakFS

 URL : http://www.tweakfs.com/

 Platform : Windows

 Type of vulnerability : Stack buffer overflow

 Risk rating : High

 Issue fixed in version : not fixed

 Vulnerability discovered by : TecR0c

 Corelan Team :

 http://www.corelan.be:8800/index.php/security/corelan-team-members/

 

01 : Vendor description of software

"Create and Extract Zips TweakFS Zip Utility for FSX was designed to be a useful tool for unpacking Zip files downloaded from FS file libraries without the need for an existing 3rd-party Zip application, but the big handy feature is that it has a tree display of the Zip folder structure giving you a clear view of how the files will unpack and into which location."

 

02 : Vulnerability details

A flaw in how the application handles a overly long zip filename which an attacker can

utilize in a manner other than the designer intended. This allows the attacker to run arbitrary-code execution on

the victims machine when a specially crafted zip file has been open within the application.

 

 

03 : Author/Vendor communication

 April 7, 2010 : author contacted

 April 16, 2010  : sent reminder

 April 19th, 2010 : No response, public disclosure

 

04: Proof of Concept

PoC Exploit

Forum Timezone: Europe/Brussels

Most Users Ever Online: 91

Currently Online:
15 Guest(s)

Currently Browsing this Page:
1 Guest(s)

Top Posters:

mr_me: 313

Lincoln: 198

rick2600: 181

redsees: 179

MaRkO T.: 174

ekse: 144

Edi: 127

Sud0: 95

sinn3r: 88

jacktheripper: 78

Member Stats:

Guest Posters: 1

Members: 9447

Moderators: 1

Admins: 1

Forum Stats:

Groups: 6

Forums: 70

Topics: 1078

Posts: 6454

Newest Members: Bunny, rzld, mryv, oneian, saruhand, gun4liv, almughairi, lightningtechie, silicrax, sncz

Moderators: Peter Van Eeckhoutte (2872)

Administrators: Peter Van Eeckhoutte (2872)