Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - TrendMicro Vulnerability in VSAPI ARJ parsing could allow Remote Code execution

 
Thread Tools Search this Thread
Old 03-03-2005, 03:16 AM   #1
Default TrendMicro Vulnerability in VSAPI ARJ parsing could allow Remote Code execution


Vulnerability Identifier: CAN-2005-0533
Discovery Date: Feb 23, 2005
Risk: Critical

"Description:


This vulnerability exists in the ARJ archive file format parser.

The ARJ archive file format is too flexible, especially in the file name field in the local
header. This file name is stored as a null-terminated string and limited only by the overall
size of the local header (local header size is stored as a 16-bit value and is limited to
2,600 bytes only).

If the file name exceeds the maximum allocated size, the VSAPI scan engine still copies this
file name into a 512-byte buffer, overwriting the succeeding data structure. One of the
fields in the said data structure is a pointer to another data stucture. The next
instruction after the copying of the file name is an assignment instruction to a member of
the structure that is referred to by the overwritten pointer. The said routine causes an
illegal memory access.

Thus, it is possible to create a specially-crafted ARJ archive file that overwrites data
after the allocated 512-byte buffer. This specially-crafted file could possibly execute an
arbitrary code.

The ISS advisory can be seen here: http://xforce.iss.net/xforce/alerts/id/189 "


http://www.trendmicro.com/vinfo/seca...Code+execution


--
Dave







David H. Lipman
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Computer Security aldrich.chappel.com.use@gmail.com A+ Certification 0 11-27-2007 02:11 AM
Remote Control Code for Magnavox MSD124 ? nr DVD Video 1 04-07-2007 06:03 AM
Remote control code dave@bowsy.co.uk DVD Video 1 08-06-2006 01:19 PM
Code for RDR-HXD710 for Sony Universal Remote RM-AV2100 paul.cornet@gmail.com DVD Video 1 10-23-2005 09:52 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46