RARLAB UnRAR File Name Format String Vulnerability
BID:10442
Info
RARLAB UnRAR File Name Format String Vulnerability
| Bugtraq ID: | 10442 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 31 2004 12:00AM |
| Updated: | May 31 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to KF <[email protected]>. |
| Vulnerable: |
RARLAB UnRar 2.90 RARLAB UnRar 2.80 RARLAB UnRar 2.71 RARLAB UnRar 2.70 RARLAB UnRar 2.60 |
| Not Vulnerable: |
RARLAB UnRar 3.0 |
Discussion
RARLAB UnRAR File Name Format String Vulnerability
RARLAB UnRAR is reportedly affected by a file name format string vulnerability. This issue is due to a failure of the affected application to properly implement a formatted string function.
This vulnerability will allow for execution of arbitrary code on a system running the affected software. This would occur in the security context of the user invoking the vulnerable application.
RARLAB UnRAR is reportedly affected by a file name format string vulnerability. This issue is due to a failure of the affected application to properly implement a formatted string function.
This vulnerability will allow for execution of arbitrary code on a system running the affected software. This would occur in the security context of the user invoking the vulnerable application.
Exploit / POC
RARLAB UnRAR File Name Format String Vulnerability
An exploit RAR archive has been made publically available.
An exploit RAR archive has been made publically available.
Solution / Fix
RARLAB UnRAR File Name Format String Vulnerability
Solution:
An upgrade is available that resolves this issue.
RARLAB UnRar 2.60
RARLAB UnRar 2.70
RARLAB UnRar 2.71
RARLAB UnRar 2.80
RARLAB UnRar 2.90
Solution:
An upgrade is available that resolves this issue.
RARLAB UnRar 2.60
-
RARLAB UnRaR >=3.0
http://www.rarlab.com/rar_add.htm
RARLAB UnRar 2.70
-
RARLAB UnRaR >=3.0
http://www.rarlab.com/rar_add.htm
RARLAB UnRar 2.71
-
RARLAB UnRaR >=3.0
http://www.rarlab.com/rar_add.htm
RARLAB UnRar 2.80
-
RARLAB UnRaR >=3.0
http://www.rarlab.com/rar_add.htm
RARLAB UnRar 2.90
-
RARLAB UnRaR >=3.0
http://www.rarlab.com/rar_add.htm