RARLAB WinRAR File Name Remote Client-Side Buffer Overflow Vulnerability
BID:12002
Info
RARLAB WinRAR File Name Remote Client-Side Buffer Overflow Vulnerability
| Bugtraq ID: | 12002 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 17 2004 12:00AM |
| Updated: | Dec 17 2004 12:00AM |
| Credit: | Vafa Khoshaein <[email protected]> is credited with the discovery of this issue. Dark Eagle also discovered this issue independently. |
| Vulnerable: |
RARLAB WinRar 3.41 RARLAB WinRar 3.40 RARLAB WinRar 3.20 RARLAB WinRar 3.11 RARLAB WinRar 3.10 beta 5 RARLAB WinRar 3.10 beta 3 RARLAB WinRar 3.10 beta 3 RARLAB WinRar 3.10 RARLAB WinRar 3.0 .0 RARLAB WinRar 3.0 |
| Not Vulnerable: |
RARLAB WinRar 3.42 |
Discussion
RARLAB WinRAR File Name Remote Client-Side Buffer Overflow Vulnerability
A remote, client-side buffer overflow vulnerability has been reported in the reported file name processing functionality of RARLAB WinRAR. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
A remote, client-side buffer overflow vulnerability has been reported in the reported file name processing functionality of RARLAB WinRAR. This issue is due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into static process buffers.
An attacker may exploit this issue to execute arbitrary code with the privileges of the user that activated the vulnerable application. This may facilitate unauthorized access or privilege escalation.
Exploit / POC
RARLAB WinRAR File Name Remote Client-Side Buffer Overflow Vulnerability
The following exploit has been made available:
The following exploit has been made available:
Solution / Fix
RARLAB WinRAR File Name Remote Client-Side Buffer Overflow Vulnerability
Solution:
This issue has been addressed in version 3.42.
RARLAB WinRar 3.0 .0
RARLAB WinRar 3.0
RARLAB WinRar 3.10
RARLAB WinRar 3.10 beta 3
RARLAB WinRar 3.10 beta 5
RARLAB WinRar 3.10 beta 3
RARLAB WinRar 3.11
RARLAB WinRar 3.20
RARLAB WinRar 3.40
RARLAB WinRar 3.41
Solution:
This issue has been addressed in version 3.42.
RARLAB WinRar 3.0 .0
-
RARLAB WinRar 3.42
http://www.rarsoft.com/rar/wrar342.exe
RARLAB WinRar 3.0
-
RARLAB WinRar 3.42
http://www.rarsoft.com/rar/wrar342.exe
RARLAB WinRar 3.10
-
RARLAB WinRar 3.42
http://www.rarsoft.com/rar/wrar342.exe
RARLAB WinRar 3.10 beta 3
-
RARLAB WinRar 3.42
http://www.rarsoft.com/rar/wrar342.exe
RARLAB WinRar 3.10 beta 5
-
RARLAB WinRar 3.42
http://www.rarsoft.com/rar/wrar342.exe
RARLAB WinRar 3.10 beta 3
-
RARLAB WinRar 3.42
http://www.rarsoft.com/rar/wrar342.exe
RARLAB WinRar 3.11
-
RARLAB WinRar 3.42
http://www.rarsoft.com/rar/wrar342.exe
RARLAB WinRar 3.20
-
RARLAB WinRar 3.42
http://www.rarsoft.com/rar/wrar342.exe
RARLAB WinRar 3.40
-
RARLAB WinRar 3.42
http://www.rarsoft.com/rar/wrar342.exe
RARLAB WinRar 3.41
-
RARLAB WinRar 3.42
http://www.rarsoft.com/rar/wrar342.exe
References
RARLAB WinRAR File Name Remote Client-Side Buffer Overflow Vulnerability
References:
References:
- Vendor Home Page (RARLAB)
- WinRAR <= 3.41 Compressed File Deletion Buffer Overflow Exploit (K-Otik Security)
- WinRAR Homepage (WinRAR)