Home page logo
/

fulldisclosure logo Full Disclosure mailing list archives

Re: unarj dir-transversal bug (../../../..)
From: evilninja <evilninja () gmx net>
Date: Tue, 12 Oct 2004 13:48:30 +0200

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

doubles () hush com wrote:
On Mon, 11 Oct 2004 16:29:40 -0700 evilninja <evilninja () gmx net> wrote:

evil () sheep:~$ unarj x test.arj
ARJ32 v 3.10, Copyright (c) 1998-2004, ARJ Software Russia. [27
Jun 2004]

arj != unarj! debian is stubido dist nd it pakage ''arj'' as ''unarj''!

um, actually i had to install a package called "unarj", obviously it's
from the same source package. i wonder why this is the case at all. when i
have "gzip", i don't _install_ "ungzip" too. but this is another discussion...

real unarj 2.* inkl 2.65 latest are vunerabble!

how nice i have stubido gnu/linux running, not having such an "original"
version of unarj ;-)

- --
BOFH excuse #290:

The CPU has shifted, and become decentralized.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

iD8DBQFBa8SNC/PVm5+NVoYRAvJLAJ9khOeZwKhaSWGaKk5PNCmKdHFbTgCgmx0F
G8/N4bLBtRoSUMVmvSsm2nI=
=1qwI
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]