SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#215006

unace buffer overflow vulnerability

Overview

A buffer overflow in the unace compression library may allow a remote attacker to execute arbitrary code.

I. Description

The unace compression library is used to decompress ace archives (*.ace file extension). A lack of input validation on filenames in an ace archive may allow a buffer overflow to occur. If an attacker supplies the unace library with a specially crafted compressed ace archive, that attacker may be able to trigger the buffer overflow and, consequently, execute arbitrary code with the privileges of the application linked to unace.

II. Impact

If a remote attacker can convince a user to access a specially crafted ace archive, that attacker may be able to execute arbitrary code. In addition, this vulnerability may prevent security software, such as anti-virus software, from detecting a malicious ace archive.

III. Solution

Apply patches from your vendor

The unace compression library is freely available and used by many vendors in a wide variety of applications. As a result, any one of these applications may contain this vulnerability. Users are encouraged to contact their vendors to determine if they are vulnerable and what action to take.

Do not accept ace archives from untrusted sources

Exploitation occurs by accessing a specially crafted ace archive. By only accessing ace archives from trusted or known sources, the chances of exploitation are reduced.

Systems Affected

VendorStatusDate NotifiedDate Updated
Aladdin Knowledge SystemsUnknown23-Sep-2005
Apple Computer, Inc.Not Vulnerable28-Oct-2005
Avast! Antivirus SoftwareUnknown21-Sep-2005
Check Point Software TechnologiesUnknown21-Sep-2005
Command Software SystemsUnknown21-Sep-2005
Computer AssociatesUnknown21-Sep-2005
Cray Inc.Unknown21-Sep-2005
CyberSoft, Inc.Unknown21-Sep-2005
DataFellowsUnknown21-Sep-2005
Debian LinuxNot Vulnerable26-Sep-2005
EMC, Inc. (formerly Data General Corporation)Unknown21-Sep-2005
Engarde Secure LinuxUnknown21-Sep-2005
F-PROT by FRISK Software InternationalNot Vulnerable23-Sep-2005
F-Secure CorporationUnknown21-Sep-2005
F5 Networks, Inc.Unknown21-Sep-2005
Finjan SoftwareUnknown21-Sep-2005
Fortinet, Inc.Unknown21-Sep-2005
FreeBSD, Inc.Vulnerable3-Oct-2005
FujitsuUnknown21-Sep-2005
Gentoo LinuxVulnerable21-Oct-2005
GFI Software, Inc.Unknown21-Sep-2005
Hewlett-Packard CompanyUnknown21-Sep-2005
HitachiNot Vulnerable22-Sep-2005
IBM CorporationUnknown21-Sep-2005
IBM Corporation (zseries)Unknown21-Sep-2005
IBM eServerUnknown21-Sep-2005
Immunix Communications, Inc.Unknown21-Sep-2005
Ingrian Networks, Inc. Unknown21-Sep-2005
Juniper Networks, Inc.Unknown21-Sep-2005
Mandriva, Inc.Not Vulnerable28-Sep-2005
Mandriva, Inc.Unknown21-Sep-2005
MessageLabsUnknown21-Sep-2005
Microsoft CorporationUnknown21-Sep-2005
MontaVista Software, Inc.Unknown21-Sep-2005
NEC CorporationUnknown21-Sep-2005
NetBSDVulnerable23-Sep-2005
NokiaNot Vulnerable26-Sep-2005
Novell, Inc. Unknown21-Sep-2005
OpenBSDUnknown21-Sep-2005
Openwall GNU/*/LinuxNot Vulnerable22-Sep-2005
Proland Software, Inc.Unknown21-Sep-2005
QNX, Software Systems, Inc.Unknown21-Sep-2005
Red Hat, Inc.Not Vulnerable26-Sep-2005
Sequent Computer Systems, Inc.Unknown21-Sep-2005
Silicon Graphics, Inc.Unknown21-Sep-2005
Sony CorporationUnknown21-Sep-2005
Sophos, Inc.Unknown21-Sep-2005
Sun Microsystems, Inc.Unknown21-Sep-2005
SUSE LinuxVulnerable26-Sep-2005
Symantec, Inc.Unknown21-Sep-2005
The SCO Group (SCO Linux)Unknown21-Sep-2005
The SCO Group (SCO Unix)Unknown21-Sep-2005
TrendmicroUnknown21-Sep-2005
Trustix Secure LinuxUnknown21-Sep-2005
TurbolinuxUnknown21-Sep-2005
UnisysUnknown21-Sep-2005
Wind River Systems, Inc.Unknown21-Sep-2005

References


http://lists.grok.org.uk/pipermail/full-disclosure/2005-February/031908.html
http://lists.suse.com/archive/suse-security-announce/2005-Jun/0006.html
http://secunia.com/advisories/14359/
http://securitytracker.com/alerts/2005/Jul/1014544.html
http://secunia.com/advisories/15776/
http://secunia.com/advisories/15674/

Credit

This vulnerability was reported by Ulf Harnhammar.

This document was written by Jeff Gennari.

Other Information

Date Public:2005-02-22
Date First Published:2005-09-22
Date Last Updated:2005-10-28
CERT Advisory: 
CVE-ID(s):CAN-2005-0160
NVD-ID(s):CAN-2005-0160
US-CERT Technical Alerts: 
Metric:4.50
Document Revision:58

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2005 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader