lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
From: evilninja at gmx.net (evilninja)
Subject: unarj dir-transversal bug (../../../..)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

doubles@...h.com wrote:
> On Mon, 11 Oct 2004 16:29:40 -0700 evilninja <evilninja@....net> wrote:
> 
>>evil@...ep:~$ unarj x test.arj
>>ARJ32 v 3.10, Copyright (c) 1998-2004, ARJ Software Russia. [27
>>Jun 2004]
> 
> arj != unarj! debian is stubido dist nd it pakage ''arj'' as ''unarj''!

um, actually i had to install a package called "unarj", obviously it's
from the same source package. i wonder why this is the case at all. when i
have "gzip", i don't _install_ "ungzip" too. but this is another discussion...

> real unarj 2.* inkl 2.65 latest are vunerabble!

how nice i have stubido gnu/linux running, not having such an "original"
version of unarj ;-)

- --
BOFH excuse #290:

The CPU has shifted, and become decentralized.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFBa8SNC/PVm5+NVoYRAvJLAJ9khOeZwKhaSWGaKk5PNCmKdHFbTgCgmx0F
G8/N4bLBtRoSUMVmvSsm2nI=
=1qwI
-----END PGP SIGNATURE-----


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ