<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "http://bugs.gentoo.org/bugzilla.dtd">

<bugzilla version="2.22.7"
          urlbase="http://bugs.gentoo.org/"
          maintainer="bugzilla@gentoo.org"
>

    <bug>
          <bug_id>166440</bug_id>
          
          <creation_ts>2007-02-11 23:40 0000</creation_ts>
          <short_desc>app-arch/{un,}rar- remotely exploitable stack based buffer overflow (CVE-2007-0855)</short_desc>
          <delta_ts>2007-03-31 18:24:46 0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>Gentoo Security</product>
          <component>Vulnerabilities</component>
          <version>unspecified</version>
          <rep_platform>All</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          <status_whiteboard>A2 [glsa] Falco</status_whiteboard>
          
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>carlo@gentoo.org</reporter>
          <assigned_to>security@gentoo.org</assigned_to>
          <cc>bernd@linx.net</cc>
    
    <cc>chainsaw@gentoo.org</cc>
    
    <cc>gentoo@meyer-dlugosch.de</cc>

      

      
          <long_desc isprivate="0">
            <who>carlo@gentoo.org</who>
            <bug_when>2007-02-11 23:40:05 0000</bug_when>
            <thetext>Exploitation of the vulnerability could allow an attacker to execute arbitrary code with the privileges of the user opening the file. Exploitation would require that an attacker hosts a maliciously crafted document on a website and entice users to visit the site. An attacker could also e-mail the malicious document and use social engineering techniques to trick the e-mail recipient into opening the document.

There are several mitigating factors for this vulnerability. Nearly all Windows users will use the GUI based WinRAR to open archives, and it is not vulnerable. If users are using the vulnerable command line based unrar, they still need to interact with the program in order to trigger the vulnerability. They must respond to the prompt asking for the password, after which the vulnerability will be triggered. They do not need to enter a correct password, but they must at least push the enter key.


http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=472

Reproducible: Always</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-12 12:58:04 0000</bug_when>
            <thetext>Thanks Carsten, this vuln went out of my scope :(

base-system, could you bump unrar version 3.7.0 please? thanks</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>vapier@gentoo.org</who>
            <bug_when>2007-02-12 13:15:13 0000</bug_when>
            <thetext>rar-3.7.0_beta1 and unrar-3.7.3 now in portage</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-12 15:25:12 0000</bug_when>
            <thetext>Thanks vapier for the very quick bump, and for unrar too.

hi arches, please test and mark stable :

rar-3.7.0_beta1  for AMD64 and X86

unrar-3.7.3  for all arches</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>jer@gentoo.org</who>
            <bug_when>2007-02-12 16:01:37 0000</bug_when>
            <thetext>Stable for HPPA.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gustavoz@gentoo.org</who>
            <bug_when>2007-02-12 16:20:31 0000</bug_when>
            <thetext>sparc stable.
</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-02-12 16:24:54 0000</bug_when>
            <thetext>both rar and unrar x86 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>blubb@gentoo.org</who>
            <bug_when>2007-02-12 16:49:12 0000</bug_when>
            <thetext>both stable on amd64</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>dertobi123@gentoo.org</who>
            <bug_when>2007-02-12 19:04:22 0000</bug_when>
            <thetext>ppc stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>corsair@gentoo.org</who>
            <bug_when>2007-02-13 11:08:26 0000</bug_when>
            <thetext>ppc64 stable</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>gentoo@meyer-dlugosch.de</who>
            <bug_when>2007-02-13 13:57:44 0000</bug_when>
            <thetext>this may be the wrong place to report, but i think there is a dependency to glibc 2.4 missing

/lib/libc.so.6: version `GLIBC_2.4&apos; not found (required by /opt/bin/rar)

i can only use sys-libs/glibc-2.3.6-r5

Portage 2.1.2-r9 (selinux/2005.1/x86/hardened, gcc-3.4.6, glibc-2.3.6-r5, 2.6.18-hardened i686)</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>wolf31o2@gentoo.org</who>
            <bug_when>2007-02-13 22:14:27 0000</bug_when>
            <thetext>alpha done</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>falco@gentoo.org</who>
            <bug_when>2007-02-13 23:56:05 0000</bug_when>
            <thetext>GLSA 200702-04, thanks to everybody. ARM, IA64, S390, don&apos;t forget to mark stable.</thetext>
          </long_desc>
          <long_desc isprivate="0">
            <who>armin76@gentoo.org</who>
            <bug_when>2007-03-31 18:24:46 0000</bug_when>
            <thetext>arm/ia64/s390 done</thetext>
          </long_desc>
      
    </bug>

</bugzilla>