StuffIt 6.5.x and Earlier Allows Buffer Overflow 62
A user writes in that Aladdin Systems has announced that StuffIt, versions 6.5.x and earlier for Mac OS and Mac OS X, "may contain a flaw that would cause expanding certain maliciously crafted .zip archives to execute unwanted instructions or code." Aladdin notes that no such "trojan horses" have been reported. StuffIt Expander 7.0 is, as with previous versions, free to download and use.
Re:If you were my son, (Score:1, Offtopic)
Re:Thats pretty good. (Score:2)
The Terrible Secret of Space, by The Laziest Men on Mars [mp3s.com], of course. Even better is the Flash music video [jonathonrobinson.com].
Re: Ermm... tsarkon you butt fucking camel lick. (Score:2)
Is this really a problem? (Score:3, Informative)
You shouldn't be using zip files on mac in general unless it is some sort of code or something. Malicious code would require a specific target platform of the mac to do anything substantial, and being that nobody in their right mind would create zip files for mac, i don't see much problem.
Re:Is this really a problem? (Score:2, Insightful)
Re:Is this really a problem? (Score:1)
timing (Score:1, Flamebait)
as I understand it (Score:1)
Re:as I understand it (Score:1, Offtopic)
Just Use Info-zip For ".zip"s (Score:5, Informative)
If you're using MacOS 9 or earlier, the potential for buffer overflows is meaningless. It wouldn't be the first time your system bailed, anyway.
For the OS X user, just adjust your browser to make Info-zip the zip file helper, and surf over to Info-zip's [info-zip.org] site to download the source or binary.
Info-zip is already installed (Score:2, Interesting)
Why bother, when it's already installed as part of Mac OS X? There's no manpage, but the executable is /usr/bin/zip (and /usr/bin/unzip). The 10.2.1 version says:
Conspiracy theory (Score:2, Interesting)
What about Stuffit Deluxe? I have to upgrade now? (Score:4, Interesting)
Well, what about those of us who bought Stuffit Deluxe 6.5? What if I bought FIFTY COPIES OF IT (for a lab), and I don't feel like paying for an upgrade to 7.0 yet? Looks like I'm screwed. This is not acceptible behaviour! Even Microsoft doesn't (always) act like this when security holes crop up in the previous version of their product. If Aladdin doesn't offer a patch for 6.5, I will be quite annoyed.
Imagine what would happen if MS stopped fixing security holes in Windows 2000 all of a sudden when Windows XP came out? They would be shot in the street!
Sorry for the sweeping generalization, but this *really* does not please me.
Re:What about Stuffit Deluxe? I have to upgrade no (Score:1)
Re:What about Stuffit Deluxe? I have to upgrade no (Score:3, Interesting)
I feel your pain.
Re:What about Stuffit Deluxe? I have to upgrade no (Score:1)
According to their website, StuffIt 6.5 was first shipped in September 2001. Office 97 was shipped, well, around 1997. Big difference.
Used to be a fan (Score:1)
With OS X why bother using StuffIt when you can create a compressed disk image? There's always Expander--which is a very nice, and free, product--when you have to extract SIT files.
Heh, buffer overflow in Windows's ZIP handling too (Score:4, Funny)
Unchecked Buffer in File Decompression Functions Could Lead to Code Execution (Q329048) [microsoft.com]:
Two vulnerabilities exist in the Compressed Folders function:
Stuffit Exploits (Score:4, Interesting)
On the one hand, Stuffit has a really incredibly amazingly good interface. You can navigate through a Stuffit archive like the Finder -- it's hierarchical, supports file operations, etc. WinZip, on the other hand, has a truly amazingly awful interface. Whoever decided that it would be a really cool idea to represent files in a flat interface and then throw a big fat toolbar in (I *hate* toolbars...awful UI element) above them should be whacked.
Anyway, the down side of Stuffit is that it is THE Mac file compression format. Compact Pro has unfortunately fallen by the wayside, and even that contender was, amazingly enough, propriatary. Why the hell can't anyone slap together tar + gzip + macbinary for the MacOS with a GUI (or something a smidgen more complicated, fair enough), so that Mac users aren't beholden to the whims of a single company? If Aladdin wanted to, they could charge $200 for their product. Not for long, but it's disgusting that they have no competition.
Stuffit's had a long history of being exploitable. Hand it corrupted resources and try to open the file...it crashes. Create an archive containing tens of thousands of locked invisible files at the root of the archive (actually, I think Stuffit clears the lock bit, though invis is still valid), and watch what happens when a poor user drops the archive on Stuffit Expander.
Re:Stuffit Exploits (Score:2)
Re:Stuffit Exploits (Score:2)
Going a little off topic, I'm having hard time stopping StuffIt Expander to expand *.tar.gz archives. I'd rather like to do that by hand from command line. But whatever I may try (using inspector panel, from the IE preferences), when I download a tar.gz file, Expander will automatically expand tar.gz to gz to folder. This is pretty annoying. Does anyone know how to stop this?
Re:Stuffit Exploits (Score:1)
Re:Stuffit Exploits (Score:1)
Re:Stuffit Exploits (HFSTAR) (Score:1)
Re:Stuffit Exploits (Score:2)
Re:Stuffit Exploits (Score:2, Informative)
Stone Design's "PackUpAndGo" is also an excellent product: http://www.stone.com/PackUpAndGo/PackUpAndGo.html
Re:Stuffit Exploits (Score:2)
Re:Stuffit Exploits (Score:2)
For major file formats, it just seems safer to have competing products and a spec out so that more people can make new products. Stuffit is just about the only major-major-major file format on any current platform I know of that's completely closed. Just about every user on the platform runs into Stuffit files, and there's only one commercial product from one company that can create them.
Heck, what if Aladdin started putting adware into Stuffit Expander, or Apple did? They already have "partners" with Sherlock and with default bookmarks...
Non-registration download for Stuffit Expander (Score:5, Informative)
ftp://ftp.aladdinsys.com/
Re:Non-registration download for Stuffit Expander (Score:1)
I always lie anyway. If they want to know who I am, they can offer me a high-quality product.
Re:Non-registration download for Stuffit Expander (Score:2)
How do buffer underun exploits work? (Score:1)
Re:How do buffer underun exploits work? (Score:2)
Sure! (Score:1)
Convenient isn't it (Score:1)
Stuffit? Bah (Score:1)
You can't get Expander as a separate download.
Aladdin is making up the known trojans claim, there aren't any besides, anything like that would have to be downloaded first to begin with.
Me? I just use gzip unless someone insists on posting something in
There is also a GuI app called OpenUp that is open source but, can't open