- ------------------------------------------------------------
-------------Debian Security Advisory DSA-3725-1 security@debian.orghttps://www.debian.org/security/ Luciano BelloNovember 27, 2016 https://www.debian.org/security/faq- -------------------------------------------------------------------------Package : icuCVE ID : CVE-2014-9911 CVE-2015-2632 CVE-2015-4844 CVE-2016-0494 CVE-2016-6293 CVE-2016-7415Debian Bug : 838694Several vulnerabilities were discovered in the International Componentsfor Unicode (ICU) library.CVE-2014-9911 Michele Spagnuolo discovered a buffer overflow vulnerability which might allow remote attackers to cause a denial of service or possibly execute arbitrary code via crafted text.CVE-2015-2632 An integer overflow vulnerability might lead into a denial of service or disclosure of portion of application memory if an attacker has control on the input file.CVE-2015-4844 Buffer overflow vulnerabilities might allow an attacker with control on the font file to perform a denial of service attacker or, possibly, execute arbitrary code.CVE-2016-0494 Integer signedness issues were introduced as part of the CVE-2015-4844 fix.CVE-2016-6293 A buffer overflow might allow an attacker to perform a denial of service or disclosure of portion of application memory.CVE-2016-7415 A stack-based buffer overflow might allow an attacker with control on the locale string to perform a denial of service and, possibly, execute arbitrary code.For the stable distribution (jessie), these problems have been fixed inversion 52.1-8+deb8u4.For the unstable distribution (sid), these problems have been fixed inversion 57.1-5.We recommend that you upgrade your icu packages.Further information about Debian Security Advisories, how to applythese updates to your system and frequently asked questions can befound at: https://www.debian.org/security/
SEC Consult Vulnerability Lab Security Advisory < 20161128-0 >============================================================
=========== title: Denial of service & heap-based buffer overflow product: Guidance Software EnCase Forensic Imager & EnCase Forensic vulnerable version: EnCase Forensic Imager<= 7.10 EnCase Forensic (tested with version 7.08.00.137) fixed version: - CVE number: - impact: high homepage: https://www.guidancesoftware.com/encase-forensic-imager found: 2016-09-30 by: Wolfgang Ettlinger (Office Vienna) SEC Consult Vulnerability Lab An integrated part of SEC Consult Bangkok - Berlin - Linz - Luxembourg - Montreal - Moscow Kuala Lumpur - Singapore - Vienna (HQ) - Vilnius - Zurich https://www.sec-consult.com=======================================================================Vendor description:-------------------"When time is short and you need to acquire entire volumes or selectedindividual folders, EnCase Forensic Imager is your tool of choice. Based ontrusted, industry-standard EnCase Forensic technology, EnCase Forensic Imager:* Is free to download and use* Requires no installation* Is a standalone product that does not require an EnCase Forensic license* Enables acquisition of local drives (network drives are not able to be acquired with Imager)* Provides easy viewing and browsing of potential evidence files, including folder structures and file metadata* Can be deployed via USB stick and used to perform acquisition of a live device"URL: https://www.guidancesoftware.com/encase-forensic-imagerBusiness recommendation:------------------------SEC Consult recommends not to use Encase Forensic Imager or the Encase ForensicSuite until a thorough security review has been performed by securityprofessionals and all identified issues have been resolved.Vulnerability overview/description:-----------------------------------1) Denial of ServiceSeveral manipulated hard disk images cause Encase Forensic Imager to crash. Asuspect manipulating the hard drive could potentially hinder an investigatorfrom using Encase Forensic Imager for creating hard disk images.Encase Forensic (v7) has been tested and found to be affected as well.2) Heap-based buffer overflowUsing a manipulated ReiserFS image an attacker can overwrite heap memory on theinvestigator's machine. Because of several restrictions SEC Consult was unableto create an exploit that works reliably within a reasonable timeframe.However, as with most heap-based buffer overflow vulnerabilities it is possiblethat an attacker could gain arbitrary code execution nevertheless.Proof of concept:-----------------SEC Consult has created proof of concept disk images that will crash Encase. ThosePoC images will not be released. 1) Denial of ServiceThe following list demonstrates cases that cause Encase to crash. Theinvestigators would be unable to analyze the hard disk/partition/image using theaffected products: * Ext3: - Several conditions cause Encase Forensic Imager to encounter an div/0 exception. Disk images that were manipulated in the following way demonstrate this issue. Those crashes have not been further investigated as to whether code execution is possible. + nummer of blocks per group: 0xFFFFFFFF + total numer of blocks: 0xFFFFFFFF + last mount path: 'A'*100000 + volume name: 'A'*100000 + block number of the superblock: 0 + FS-Id: 'A'*100000 - Manipulating the size of the inode structure value (e.g. 0xFFFF) causes Encase Forensic Imager to write beyond the limits of a previously allocated (VirtualAlloc) segment. * Iso9660: - If the length of a file name is specified in a way that it would exceed the end of the last block, Encase Forensic Imager crashes while trying to read beyond an allocated segment. * ReiserFs: - When setting a block size of below 0x200 the application overwrites heap memory with attacker-supplied data. * GPT: - When specifying an overly long name (in our setup longer than 0x3fc6) for a partition, Encase Forensic crashes failing to read memory when trying to determine the length of the string. The partition table can be constructed in a way that it can also be used for storing data. However, an investigator using Encase will not be able to analyze it.2) Heap-based buffer overflowThe manipulated ReiserFs image that causes the application to overwrite heapmemory can be tuned to overwrite heap-data with attacker-controlled data.The application calculates a value (here called "dev_block_count") as:dev_block_count = blocksize from image (e.g. 0x200) / blocksize of reading device (typically 0x200) * number of blocks.text:006F5306 mov ecx, [esi+14Ch] ; ecx = blocksize (device, 0x200).text:006F530C movzx eax, [esp+90h+var_54] ; eax = blocksize (img).text:006F5311 xor edx, edx.text:006F5313 div ecx ; div eax / ecx.text:006F5315 push 0.text:006F5317 mov edx, eax.text:006F5319 imul edx, [esp+94h+var_80] ; * numblocksIf this value is zero (which is the case when the blocksize from the image issmaller than 0x200), later in the program it is corrected to the value 1(@0064B7AA).This causes the application to later allocate 4 bytes of memory (the correctedvalue of 1 * 4, @006F5426).Then the first block of the image is copied to the allocated 4-byte heap space.The length to be copied is calculated based on the number of blocks specifiedin the image (maximum 0x200).Vulnerable / tested versions:-----------------------------At least version 7.10 of Encase Forensic Imager has been found to be vulnerable.This version was the latest at the time the security vulnerabilities werediscovered.The disk images that caused crashes for Encase Forensic Imager also causedcrashes with Encase Forensic version 7.08.00.137. It is unknown whetherEncase Forensic v8 is affected as well.Vendor contact timeline:------------------------2016-10-07: Contacting vendor (sales team) through email, requesting security contact, sending responsible disclosure policy & encryption keys2016-10-14: No answer, extending email recipient list, requesting security contact again2016-10-14: Vendor: our request has been sent to management team, they will follow up2016-10-17: Vendor: one of their security representatives will be reaching out shortly.2016-10-28: Asking again for security contact, kind reminder of latest release date per 2016-11-262016-10-28: Vendor: Verified that request has been passed on to proper department, they will follow up on this2016-11-07: Asking again for security contact, reminding them again that release date is in about three weeks2016-11-08: Extending email recipient list again, including SVP Product Engineering explaining unsuccessful attempts to receive a security contact2016-11-14: Still no answer, reminding Guidance Software again about the release date which has been set to 2016-11-28 now. Told them that the initial vulnerabilities also affect Encase Forensic and not only Encase Forensic Imager.2016-11-14: Vendor: "send the alleged vulnerability to us for review" (signed email)2016-11-14: Sending the advisory encrypted to the vendor, including proof of concept disk images to reproduce the issues2016-11-14: Vendor: "We will look at the issues and will address them in future release(s) if necessary"2016-11-15: Asking if there is a hotfix planned, offering to delay the advisory release for a few days if necessary, otherwise we'll keep the set release date2016-11-15: Vendor: they will fix the issue later and are fine patching it after advisory release2016-11-25: Asking if any fixes are available2016-11-28: Releasing security advisorySolution:---------The vendor told SEC Consult they investigate the issues and will fix them at alater date.Workaround:-----------NoneAdvisory URL:-------------https://www.sec-consult.com/en/Vulnerability-Lab/Advisories.htm~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~SEC Consult Vulnerability LabSEC ConsultBangkok - Berlin - Linz - Luxembourg - Montreal - MoscowKuala Lumpur - Singapore - Vienna (HQ) - Vilnius - ZurichAbout SEC Consult Vulnerability LabThe SEC Consult Vulnerability Lab is an integrated part of SEC Consult. Itensures the continued knowledge gain of SEC Consult in the field of networkand application security to stay ahead of the attacker. The SEC ConsultVulnerability Lab supports high-quality penetration testing and the evaluationof new offensive and defensive technologies for our customers. Hence ourcustomers obtain the most current information about vulnerabilities and validrecommendation about the risk profile of new technologies.~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Interested to work with the experts of SEC Consult?Send us your application https://www.sec-consult.com/en/Career.htmInterested in improving your cyber security with the experts of SEC Consult?Contact our local offices https://www.sec-consult.com/en/About/Contact.htm~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~Mail: research at sec-consult dot comWeb: https://www.sec-consult.comBlog: http://blog.sec-consult.comTwitter: https://twitter.com/sec_consultEOF W. Ettlinger / @2016