what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

secunia-SpeedProject.txt

secunia-SpeedProject.txt
Posted Nov 30, 2005
Authored by Tan Chew Keong | Site secunia.com

Secunia Research has discovered two boundary error vulnerabilities in various SpeedProject products, which can be exploited by malicious people to compromise a user's system.

tags | advisory, vulnerability
SHA-256 | 40fcd4925c69b8512716ccb146a61281115a9d0d9c4924ad8db2a33fbfbe07b6

secunia-SpeedProject.txt

Change Mirror Download
====================================================================== 

Secunia Research 24/11/2005

- SpeedProject Products ZIP/UUE File Extraction Buffer Overflow -

======================================================================
Table of Contents

Affected Software....................................................1
Severity.............................................................2
Description of Vulnerability.........................................3
Solution.............................................................4
Time Table...........................................................5
Credits..............................................................6
References...........................................................7
About Secunia........................................................8
Verification.........................................................9

======================================================================
1) Affected Software

* ZipStar 5.0 Build 4285
* Squeez 5.0 Build 4285
* SpeedCommander 11.0 Build 4430
* SpeedCommander 10.51 Build 4430

Prior versions may also be affected.

======================================================================
2) Severity

Rating: Moderately Critical
Impact: System access
Where: Remote

======================================================================
3) Description of Vulnerability

Secunia Research has discovered two vulnerabilities in various
SpeedProject products, which can be exploited by malicious people to
compromise a user's system.

1) A boundary error exists in CxZIP60.dll and CxZIP60u.dll due to the
unsafe use of the "lstrcat()" function when constructing the full
pathname of a file that is extracted from a ZIP archive. This can be
exploited to cause a stack-based buffer overflow and allows arbitrary
code execution when a specially crafted archive is extracted.

The vulnerability has been confirmed in the following products.
* ZipStar 5.0 Build 4285
* Squeez 5.0 Build 4285
* SpeedCommander 11.0 Build 4430
* SpeedCommander 10.51 Build 4430

2) A boundary error exists in CxUux60.dll and CxUux60u.dll due to
the unsafe use of the "lstrcpy()" function when constructing the
full pathname of the file that is decoded from a UUE file. This can
be exploited to cause a stack-based buffer overflow and allows
arbitrary code execution when a specially crafted UUE file is
decoded.

The vulnerability has been confirmed in the following products.
* Squeez 5.0 Build 4285
* SpeedCommander 11.0 Build 4430
* SpeedCommander 10.51 Build 4430

======================================================================
4) Solution

Update to the fixed versions.

SpeedCommander 10:
Update to version 10.52 Build 4450.

SpeedCommander 11:
Update to version 11.01 Build 4450.

Squeez 5.0:
Update to Squeez 5.10 Build 4460.

ZipStar 5.0:
Update to ZipStar 5.10 Build 4460.

======================================================================
5) Time Table

03/11/2005 - Initial vendor notification.
03/11/2005 - Initial vendor reply.
17/11/2005 - Vendor released fixed versions.
24/11/2005 - Public disclosure.

======================================================================
6) Credits

Discovered by Tan Chew Keong, Secunia Research.

======================================================================
7) References

No other references.

======================================================================
8) About Secunia

Secunia collects, validates, assesses, and writes advisories regarding
all the latest software vulnerabilities disclosed to the public. These
advisories are gathered in a publicly available database at the
Secunia website:

http://secunia.com/

Secunia offers services to our customers enabling them to receive all
relevant vulnerability information to their specific system
configuration.

Secunia offers a FREE mailing list called Secunia Security Advisories:

http://secunia.com/secunia_security_advisories/

======================================================================
9) Verification

Please verify this advisory by visiting the Secunia website:
http://secunia.com/secunia_research/2005-60/advisory/

Complete list of vulnerability reports published by Secunia Research:
http://secunia.com/secunia_research/

======================================================================



Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close