11 ms·
7-Zip: Multiple Memory Corruptions via RAR and ZIP
- d33 9y agoWhy wasn't it found with afl-fuzz?
- landave 9y agoThe RAR PPMd bug can only be triggered if many conditions are satisfied. For example, the RAR archive needs to be mostly correctly structured, and needs to have at least two items that are compressed with the right flags (e.g., RAR version 3, PPMd). Furthermore, the compressed streams need to be constructed such that the bugs are triggered. Hence, I believe the bug is difficult to hit with straightforward coverage-guided fuzzing.
- blattimwind 9y agoBecause AFL does not find every path-execution-based vulnerability?
- carussell 9y agoTwo comments: The way its written, I first took the mention of finding this "during the analysis of a prominent antivirus product" to mean that you were reverse engineering some AV thing and found that it was scanning for this vulnerability (i.e., to protect against bad archives). After a second read, it seems like maybe not, and that the AV itself re-used parts of 7-zip for its own implementation and was therefore vulnerable itself. Still not sure, though. The way the stylesheet makes the "rendered" form (especially section headings) resemble markdown source is pretty neat.
- arka2147483647 9y agoIt's common knowledge that AV programs scan files inside compressed archives. Obviously you need to run the decompression code to do that.
- blattimwind 9y agoIt's also common knowledge that the AV industry has a huge software quality and engineering problem ("let's unpack malware and emulate x86 in kernel space, because that never backfired before!").
- katastic 9y agoI've actually heard many people (including one Chrome developer) that they don't even use AV anymore except Windows Defender because 99% of AV break Windows/applications by using non-standard hooks and may even introduce new vulnerabilities with their kernel drivers/etc. https://it.slashdot.org/story/17/02/01/1334219/google-chrome-engineer-says-windows-defender-the-only-well-behaved-antivirus-cites-tons-of-empirical-data https://it.slashdot.org/story/17/02/01/1334219/google-chrome... Honestly, if they can't even stop viruses from infiltrating closed systems like Android and iOS, I don't see how an anti-virus suite could ever win the battle against a user intentionally installing a virus. (Of course, desktop apps are a different ballpark than web apps/websites where you're merely connecting to a website vs installing a dedicated application with filesystem access.)
- alkonaut 9y agoI don’t think I know of windows users that use anything other than defender these days on their personal machines, but I (am forced to) use McAfee on my work machine. I suspect that the enterprise tooling is better for third party AV and that’s the only thing other than inertia keeping corporate desktops on those old AV products.
- katastic 9y agoAddendum: Anyone remember GStreamer being a Linux vulnerability because it had a 6502 CPU emulator to run... NES music files, and hackers managed to jump outside of the VM. https://scarybeastsecurity.blogspot.com/2016/11/0day-exploit-compromising-linux-desktop.html https://scarybeastsecurity.blogspot.com/2016/11/0day-exploit... It makes me wonder how easy it is to break out of a particular anti-virus vendor's VM, in a vulnerability that wouldn't exist if you weren't even running AV (outside Defender) at all.
- landave 9y agoYou are completely right with the first comment. The antivirus product itself reuses parts of 7-Zip and is vulnerable itself. I mentioned this mainly because I did not analyze the original 7-Zip software, but only discovered that it was affected as well after I had found the bug in this antivirus product. I admit that this is confusing, so I'll probably try to rephrase this.
- woodson 9y agoSeems like a possible license violation then (7-Zip is LGPL).
- Promarged 9y ago> The way the stylesheet makes the "rendered" form (especially section headings) resemble markdown source is pretty neat. As far as I see it's just section headers, but I agree the stylesheet is very nice. The section header prefix (###) could be an anchor to the section though (<a href="#section">).
- ccleve 9y agoDoes the most recent version on the 7-Zip website, 18.00 beta, contain the patch? It's two weeks old. 7-Zip doesn't appear to contain an auto-updater or an "update me" button.
- landave 9y agoYes, 18.00 beta is the patched version. The current release (non-beta) version is not patched yet. Moreover, the POSIX port of p7zip is not patched yet at all.
- Flott 9y agoI find it a little bit concerning that the release note of V18.00 beta does not mention any fix for a security issues. I guess it's included in the "bug fixes"... https://sourceforge.net/p/sevenzip/discussion/45797/thread/628149a0/ https://sourceforge.net/p/sevenzip/discussion/45797/thread/6...
- rhabarba 9y agoHappy to have switched to WinRAR years ago. At least they do QA.
- AsyncAwait 9y agoI am sure WinRAR has no bugs whatsoever, but would still like to see some evidence to that fact.
- ComodoHacker 9y agoSome of the previous non-existent bugs: http://seclists.org/fulldisclosure/2015/Sep/106 http://seclists.org/fulldisclosure/2015/Sep/106 https://www.rarlab.com/vuln_zip_spoofing_4.20.html https://www.rarlab.com/vuln_zip_spoofing_4.20.html
- jwilk 9y ago> http://seclists.org/fulldisclosure/2015/Sep/106 http://seclists.org/fulldisclosure/2015/Sep/106 This is not a vulnerability: https://www.rarlab.com/vuln_sfx_html.htm https://www.rarlab.com/vuln_sfx_html.htm
- jccalhoun 9y agoWhat software doesn't have bugs? This was discovered and it was patched in a timely fashion.
- Cthulhu_ 9y ago...did you actually pay for it? You'd be part of a select group then :D https://www.reddit.com/r/PaidForWinRAR/ https://www.reddit.com/r/PaidForWinRAR/
- rhabarba 9y agoI did, indeed. Sadly, the subreddit ignored my submission.
- jwilk 9y agoTimeline with a sane date format: 2017-12-29 - Discovery 2017-12-29 - Report 2017-12-29 - MITRE assigned CVE-2017-17969 2018-01-10 - Patched version 7-Zip 18.00 released
- deleted 9y ago[deleted]
- landave 9y agoThanks for pointing this out. I just fixed it.
- kijin 9y ago7-Zip 18.00 is not really "released" at this time. 18.00 is marked as "beta" in the official website, and 16.04 is still at the top of the list. An average person trying to download 7-Zip right now will most likely choose the vulnerable version. Beta versions of 7-Zip frequently stay in that status for months, if not years. Between 9.20 and 15.12, 7-Zip produced nothing but beta versions for 5 years. I understand the project moves slowly, but this is not a release model that facilitates quick dissemination of important security patches.
- da_chicken 9y ago> Between 9.20 and 15.12, 7-Zip produced nothing but beta versions for 5 years. That's not all that surprising. The software was 10 years old when v9 came out and the major version number is just the year of release. There aren't 5 major releases that never got out of beta. The major version numbers in 7-Zip are misleading this way because the author doesn't really conform to standard conventions. Of course, that is pretty obvious once you use the software for awhile. It still doesn't properly support UAC.
- jccalhoun 9y agoYes, the way 7-zip releases are done is not ideal and the versioning scheme is just weird. I wish he would make his versioning clearer.
- yborg 9y agoWhile this analysis was done for 7zip, I would imagine that pretty much every packaged implementation on any platform would have these issues, since most people do exactly the same thing - reuse the reference implementation. Just checked keka on macOS, and it uses the p7zip code.
- Klasiaster 9y agoNot turning on standard mitigation techniques because of binary size is one of the strangest reasons I've heard. And then still programming in an unsafe language, quite self-confident for a "humble programmer". https://www.cs.utexas.edu/~EWD/transcriptions/EWD03xx/EWD340.html https://www.cs.utexas.edu/~EWD/transcriptions/EWD03xx/EWD340... It has already taught us a few lessons, and the one I have chosen to stress in this talk is the following. We shall do a much better programming job, provided that we approach the task with a full appreciation of its tremendous difficulty, provided that we stick to modest and elegant programming languages, provided that we respect the intrinsic limitations of the human mind and approach the task as Very Humble Programmers.
- withinrafael 9y agoHe won't go https, sign his binaries, or enable mark-of-web either. It's strange to see people still playing small binary golf in 2018.
- Froyoh 9y agoWhere do you learn about these things? This all went over my head.
- adricnet 9y agoI found Tobias Klein's _A Bug Hunter's Diary_ to be quite readable and enlightening even if I couldn't follow all of the code. https://nostarch.com/bughunter https://nostarch.com/bughunter
- landave 9y agoWhat do you mean exactly by "these things"? It may be that the blog post is difficult to understand simply because I have written it poorly...
- brokenmachine 9y agoI read posts like that and marvel at how much people can understand. Well done and thanks for posting.
- rburhum 9y agoMS COM C++ style coding for those that are interested and curious about all the S_FALSE and STDMETHODIMP macros.
- equalunique 9y ago>If you use Shkarin’s PPMd implementation, I would strongly recommend you to harden it by adding out of bound checks wherever possible, and to make sure the basic model invariants always hold. Sounds like a fun project.
- landave 9y agoSo I just tried to compile 7-Zip with VS2017 and /DYNAMICBASE. The main binary 7z.dll is 1,569,792 bytes in total, 9344 bytes (0.595%) of which are used by the relocation table. Enabling stack canaries (/GS) gives me a 1,578,496 byte binary (including the relocation table), so another 8704 bytes more.
- mjevans 9y agoIt would be interesting to have a comparison based on locally built binaries both with and without these features enabled. Performing the tests on packing the actual 7-Zip source code (as shipped without extras) would be a valid reference suite.
- landave 9y agoI assume you mean a performance comparison? The runtime performance cost of ASLR on Windows is zero once a binary has been loaded, since the code is relocated at load time. Stack canaries might cause a slight performance hit, but it is usually below one percent, since it creates only a small cost per function call for a fraction of all functions.
- quotheth 9y agoIt isn't even per function call in all implementations.
- AnIdiotOnTheNet 9y agoPeople not caring about load time costs are probably one of the reasons the guy still uses VC6, which starts up practically instantly.