Vulnerability in Archive Formats

Eduardo Casarero ecasarero at gmail.com
Tue Mar 18 20:17:46 GMT 2008


Hi everybody, does anyone has issues with this?

https://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html

What is Affected?

The vulnerabilities described in this advisory can potentially affect
programs that handle
the archive formats ACE, ARJ, BZ2, CAB, GZ, LHA, RAR, TAR, ZIP and ZOO.

The Test Suite contains a set of fuzzed archive files in different
formats, some of which
may cause and some that are known to cause problems in common tools
processing archived
content. These include:

* Content inspection products such as anti-virus and stateful firewalls
* Encryption products (VPN, PGP)
* Backup software
* Office programs
* Operating systems and libraries

I have not found to much information, does anyone has more info?

Regards,


More information about the MailScanner mailing list