12 ms·
7-Zip: From Uninitialized Memory to Remote Code Execution
- Someone1234 8y ago7-Zip needs to start a Go Fund Me or similar for a Code Signing certificate. They're like $69-89/year, which is expensive, but for such a popular piece of software it would be a nice safety net in case of site compromise. Too bad none of the big CAs have an Open Source/Charity program that would provide a Authenticode Certificate for use with that software.
- laurent123456 8y agoThat's surprising. I'd expect they receive more than $70 a year in donation already, so it should not be such a big issue.
- louhike 8y agoI've never found (recently) how to donate to 7-zip, it seems the author removed the option to do so on the website. Maybe I'm too stupid, so please correct me if I'm wrong and you find a link.
- chipperyman573 8y agoAFAIK 7-zip doesn't take donations (feel free to correct me), but you could argue that the donations were going towards the author of the software to thank them for their work and not towards funding the development, so the author has no reason to feel compelled to buy a cert if they don't want to. Of course, that would all depend on the wording of the donation page, which I don't believe exists.
- yash1th 8y ago> Go Fund Me I second it. The thing with donations is many people assume that someone is gonna donate (including me) and click "not now or later", where as in gofundme we would see how much they raised out of total goal and many people will then put the money.
- sametmax 8y agoThat could be a nice use case for a blockchain.
- dane-pgp 8y agoI can picture this working, actually. Someone could put some smart contracts into the Ethereum blockchain, for example, one per piece of software, with the instruction that if the contract receives more than a certain threshold in total donations, a transaction is sent to a CA asking them to issue a code signing cert to the developer of the relevant piece of software (hardcoded into the smart contract). The CA would have to be in on this, by having an Ethereum address to receive the crowd-funded amount at, and they would have to make contact with the developer and verify them using their normal methods, but there would be a strong financial incentive for them persuade the developer to accept their certificate. Perhaps if the developer declines, then the funds controlled by the smart contract can expire and be sent back to the unsuccessful crowd-funders.
- fuzzy2 8y agoIIRC 7-Zip has explicitly decided not go get signed. It doesn’t help all that much anyway, SmartScreen still catches your application and nags the user. Unfortunately, I cannot seem to find any reference, so I might remember it wrong or it wasn’t about 7-Zip or whatever. The thing with SmartScreen is (unfortunately) still true.
- wyday 8y agoEV Code signing certs get you immediate trust with Smart Screen. Recently discussed over on the bootstrapped forum: http://discuss.bootstrapped.fm/t/code-signing-certificate-recommendation/5806/8?u=wyattoday http://discuss.bootstrapped.fm/t/code-signing-certificate-re... Regular, non-EV code-signing certs, aren't as useful as they were when Vista / Windows 7 were the main Windows OSes.
- fuzzy2 8y agoInteresting, I wasn’t aware of that. However, isn’t getting an EV certificate impossible for a natural person? You’d have to be some sort of legally recognized organization. Not exactly suitable for small-scale Open Source development.
- gruez 8y ago>However, isn’t getting an EV certificate impossible for a natural person? You’d have to be some sort of legally recognized organization no? random example: https://sourceforge.net/projects/keepass/files/KeePass%202.x/2.38/KeePass-2.38-Setup.exe/download https://sourceforge.net/projects/keepass/files/KeePass%202.x... signer is: "Open Source Developer, Dominik Reichl" edit: another example https://yarnpkg.com/latest.msi https://yarnpkg.com/latest.msi signer is: "Daniel Lo Nigro"
- fuzzy2 8y agoKeePass: This isn’t an EV certificate (has only OID 2.23.140.1.4). Certum also clearly states, topmost on the description of how to get an EV Code Signing certificate: > We do not issue EV Code Signing certificates to natural persons! Yarn: Not an EV certificate either: "Organizationally validated certificates used to sign standard objects." (2.16.840.1.114412.3.1 in addition to 2.23.140.1.4.1).
- gruez 8y agoit's even cheaper if it's for an open source project: https://www.certum.eu/certum/cert,offer_en_open_source_cs.xml https://www.certum.eu/certum/cert,offer_en_open_source_cs.xm... 28 eur.
- landave 8y agoThere were some misunderstandings that I want to clear up (maybe I will add them in an update to the blog post): 1. Some people mentioned that this would "only affect RAR files" and it would be safe to extract 7z files with 7-Zip prior to version 18.05. This is wrong, because 7-Zip detects the file type from the magic numbers at the beginning of the file. So the exploit can be renamed to 'exploit.7z' and it works just as well. On /r/sysadmin, someone even mentioned that a temporary solution might be to block RAR files. By the same argument, this is unlikely to be effective. 2. Almost all versions prior to 18.05 are affected. I manually checked version 15.05 and 17.01, and they are definitely affected. 3. Not only 7-Zip itself is affected, but essentially all software that uses 7z.dll as library to extract files. This includes various anti-virus software. However, exploitation may be more difficult (though not impossible) if ASLR&DEP is properly enabled (on all modules).
- jessaustin 8y agoThis includes various anti-virus software. It's fascinating that this category of equipment, which searches for viruses by running untrusted code, is still regularly installed in all corners of valuable networks.
- nothrabannosir 8y agoAs far as I understand the bug, this is not about running untrusted code (but: a parsing error resulting in state corruption). Unless you refer to the 3rd party lib (7z), used by virus scanners, to analyse rar files. But typically "untrusted code" means code that was supplied "at runtime", not at compile time (like a lib), so e.g. if a virus scanner would actually execute a .exe to evaluate its effects, or run javascript found in a webpage. To be fair to virus scanner vendors, the only way to mitigate this kind of bug is NIH: don't use 3rd party libs, implement everything yourself. But then, of course, without bugs yourself, as well :)
- infogulch 8y ago> the only way to mitigate this kind of bug is NIH Or, you know, conduct audits of open source libraries they use and contribute fixes back.
- therealmarv 8y agoMy guess: Because 7zip is not a good auto update software (does it even warn if there is a new version?) this security bug is HUGE! Just give you an example: Many Germans think that http://www.7-zip.de/ http://www.7-zip.de/ is the official site and you still download 16.04 there.
- Tomte 8y agoWell, it says „official website“. If it isn‘t the author should send a C&D, this is really unfair.
- y4mi 8y agoYeah, there is no question about it. This website clearly says that it's the legit source for 7zip. There is even a red box on the right side of the page. This needs to be taken down if this is not an official source. The left side has a navigation to different translations of the page. All but the English version link to the German page as well. I'm guessing it was once part of the build pipeline but has since been abandoned. So yeah, it is an official source. It's just outdated
- dragontamer 8y agoOr you know, the author of 7-zip could pay for a digital certificate and sign the executable. Fake websites and "Trojans" are a known problem, with a known solution. Unfortunately, 7-zip barely has any security involved. No digital signatures, no ASLR, no NX bit, no stack canaries, no nothing. Hopefully these security concerns wake up Ivor. Its not the 90s anymore: developers have to participate to get a proper security posture. That's why Windows tried so hard to get everyone to use sandboxed Win10 Apps / Metro Sandbox by default, because these problems require the developers to care about security.
- simon04 8y ago> So yeah, it is an official source. It's just outdated `whois 7-zip.de` resolves to a private person in Germany. This does not look official to me. More like a crowdsourced effort of providing translated websites with a dangerous effect in case of security vulnerabilities. The versions provided are (as of 2018-05-04T10:20:00Z): en 18.05, de 16.04, zh 16.04/18.05, eo 18.01, fr 18.01, ja 18.05, pt 18.01, es 18.01, th 18.05, vi 18.01
- mraison 8y agoNowadays when that sort of bug is discovered, the question that naturally comes to my mind is "would that have happened if the software were implemented in (safe) Rust"? In that case it looks like the answer is no. Of course 7-zip is much older than Rust so that's just a thought experiment.
- dingo_bat 8y agoOf course same is true for modern cpp.
- Jweb_Guru 8y agoModern C++ does not mandate that every value be a valid instance of its type wherever it is theoretically accessible, so I'm not sure why you're saying modern C++ fixes this. Actually, the fact that Rust does is something people somewhat regularly complain about. It is a heavy-handed performance / code complexity vs. safety tradeoff that certainly fixes this bug, which I think is a pretty reasonable thing to point out.
- dingo_bat 8y agoIf you follow C++14 core guidelines, the defect described would not have occurred. The bug at its core is usage of unsanitized input data. You don't need to "mandate that every value be a valid instance of its type wherever it is theoretically accessible", however that may differ from simple sane C++14 paradigms. OPINION ALERT: Honestly guys get over rust, it does not offer a single advantage in real-life programming scenarios.
- sidlls 8y agoI disagree with people who think Rust is a savior, but it does have plenty of advantages in some areas over C and C++, especially for novices.
- deleted 8y ago[deleted]
- therealmarv 8y agoGreat, p7zip is also affected according to an earlier article [1] and the last version 16.02 is from 2016 [2] This open source libraries are used everywhere :( [1]: https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/ https://landave.io/2018/01/7-zip-multiple-memory-corruptions... [2]: https://sourceforge.net/projects/p7zip/files/p7zip/ https://sourceforge.net/projects/p7zip/files/p7zip/
- landave 8y agoNote that the standard 'p7zip' package from Debian/Ubuntu doesn't support RAR. However, they have an additional package 'p7zip-full' or 'p7zip-rar' for RAR support. I didn't check explicitly, but I assume these are affected.
- pkkm 8y agoI checked the versions in buster (p7zip-full 16.02+dfsg-6, p7zip-rar 16.02-2) and they look unaffected to me. Turns out that the Debian maintainers patch upstream sources to include hardening flags, e.g. -fstack-protector-strong -D_FORTIFY_SOURCE=2 -Wl,-z,relro. You can use hardening-check to check the binaries on your system.
- landave 8y agoOkay, so these packages come with more mitigations than 7-Zip on Windows. However, looking at the source code, I am pretty sure they are affected by the same bug.
- pkkm 8y ago"Unaffected" was probably the wrong word to use. What I meant is that one of the mitigations (making the executables position-independent) should prevent the bug from being exploitable for remote code execution on Debian.
- therealmarv 8y ago
- wolf550e 8y agoIs there software running on Linux which is derived from the same source and is also vulnerable? Is this package vulnerable: https://packages.debian.org/sid/p7zip-rar https://packages.debian.org/sid/p7zip-rar https://packages.ubuntu.com/bionic/p7zip-rar https://packages.ubuntu.com/bionic/p7zip-rar ?
- landave 8y agoJust looked at both the packages source, and it looks like they are affected. At least all the vulnerable code is in the source package.
- qz3 8y agoYes, they are. I just removed p7zip from my arch box for now. Looking at the project, I think it may take a while to get up to 18.05
- chungy 8y agoDebian (and Ubuntu as a downstream) patched out issues already: https://www.debian.org/security/2018/dsa-4104 https://www.debian.org/security/2018/dsa-4104
- landave 8y agoThat's right, they patched CVE-2017-17969, which affected ZIP decompression. Interestingly, I believe they didn't patch CVE-2018-5996 (affecting RAR), which I published [0] on January 23 together with CVE-2017-17969. [0]: https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/ https://landave.io/2018/01/7-zip-multiple-memory-corruptions...
- carey 8y agoThe Debian security team doesn’t patch packages from the non-free repository, like the 7-Zip RAR support: https://www.debian.org/security/faq#contrib https://www.debian.org/security/faq#contrib That would have to wait for the maintainer to upload a new version and get it into a stable release.
- eisa01 8y agoAre there any good alternatives to 7-zip we can use instead?
- raimue 8y agoFor extraction, use bsdtar from libarchive. It supports various container and compression formats. I never looked back to GNU tar, bsdtar is vastly superior. https://github.com/libarchive/libarchive/wiki/LibarchiveFormats https://github.com/libarchive/libarchive/wiki/LibarchiveForm...
- nebulous1 8y agoI have always used 7-Zip on Windows. Having done some reading now, the author's general attitude towards the tradeoff between security and executable size/speed have convinced me to try and not use it in the future. Thankfully I rarely have to use Windows these days.
- olfactory 8y agoWhy does anyone use 7-Zip? Does it have any advantages over the more widely used alternatives (tarball and zip)?
- Boulth 8y agoBetter compression I guess...
- fake-name 8y agoIt has convenient windows packages.
- user5994461 8y agoYou need 7-zip to read tarball and zip on Windows.
- netheril96 8y agoFor me, it is support for unicode filenames. There are extensions for tarball and zip file formats that handles the problem, but not many software supports these extensions, whereas every software supporting 7z handles unicode filenames correctly.
- StapleHorse 8y agoI would never have found out this if it wouldn't for this post in HN. So Thanks you for posting.
- SloopJon 8y agoI notice that the submission contains a "?hn" query arg, which I'm pretty sure confuses the dupe detector.
- lengocthuong15 8y agoHi all, In 18.01 Igor had fixed CVE-2018-5996 with adding some variable like _errorMode or m_TablesOK. And in 18.05 I don't see this variables. Igor was replace it by _solidAllowed to fix CVE-2018-10115. Does it fix for both CVE-2018-5996 and CVE-2018-10115? Thank you
- landave 8y agoI think this is correct. Since _solidAllowed is set to false at the beginning of Code(), it will remain false if an exception occurs in the middle of decoding (CVE-2018-5996). This will enforce PpmError being set to true for the next item, which in turn will enforce the (possibly broken) PPMD state to be reinitialized. In some sense, this means that the new bug fix is a generalization of the first one, fixing both CVE-2018-5996 and CVE-2018-10115.
- lengocthuong15 8y agoThank you!
- dsc_ 8y agoThis is why Cuckoo Sandbox uses sflock (https://github.com/jbremer/sflock https://github.com/jbremer/sflock) :) It sandboxes extraction.
- meganfox2233 8y agoI was diagnosed with Parkinson's disease nearly 4 years ago, at 51. I had a stooped posture, tremors, muscle stiffness, sleeplessness, slow movement. I was placed on Sinemet for 7 months and then Sifrol and Rotigotine was introduced which replaced the Sinemet but I had to stop due to side effects. Last year, I started on Parkinsons disease herbal treatment from Madida Herbal Clinic, this natural herbal treatment totally reversed my Parkinsons disease. Visit www.madidaherbalcenter.weebly.com or email madidaherbalcenter@gmail.com. The treatment worked incredibly for my Parkinsons disease, i have a total decline in symptoms including tremors, stiffness, slow movement and others.
- deleted 8y ago[deleted]
- visitorabc 8y agoSince Ubuntu and Debian are affected,so CentOS is affected too?
- olinguito 8y agoHas anyone definitively confirmed that this vulnerability exists in 7-Zip v9.20 (release) through v9.35 (beta)?