JDownloader Community - Appwork GmbH
 

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 17.05.2016, 23:58
jc_denton
Guest
 
Posts: n/a
Default Does 7zip UDF vulnerability affect JDownloader?

I see that JDownloader uses 7zip-JBindings, which is based upon 7zip 9.20 which is affected by a dangerous vulnerability regarding UDF format.

Is JDownloader vulnerable? Automatically unpacking a prepared .udf file that has been renamed to .zip may cause an infection.

Please tell me that I am wrong.

**External links are only visible to Support Staff****External links are only visible to Support Staff**
**External links are only visible to Support Staff****External links are only visible to Support Staff**

Fixed in 7-zip 16.00: **External links are only visible to Support Staff****External links are only visible to Support Staff**
Reply With Quote
  #2  
Old 18.05.2016, 15:22
Jiaz's Avatar
Jiaz Jiaz is offline
JD Manager
 
Join Date: Mar 2009
Location: Germany
Posts: 79,289
Default

No it does not, because JDownloader does not support/use/provide UDF Extraction
__________________
JD-Dev & Server-Admin
Reply With Quote
  #3  
Old 18.05.2016, 15:24
Jiaz's Avatar
Jiaz Jiaz is offline
JD Manager
 
Join Date: Mar 2009
Location: Germany
Posts: 79,289
Default

Any Idea how to create an udf File? then I will check against your thought about ".udf renamed to xy" and will see what happens.
__________________
JD-Dev & Server-Admin
Reply With Quote
  #4  
Old 18.05.2016, 22:01
jc_denton
Guest
 
Posts: n/a
Default

Thx. I ask because yesterday the first spam with udf renamed to zip hit my mailbox.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

All times are GMT +2. The time now is 13:30.
Provided By AppWork GmbH | Privacy | Imprint
Parts of the Design are used from Kirsch designed by Andrew & Austin
Powered by vBulletin® Version 3.8.10 Beta 1
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.