RARLAB WinRAR File Name Potential Buffer Overflow Vulnerability
BID:15999
Info
RARLAB WinRAR File Name Potential Buffer Overflow Vulnerability
| Bugtraq ID: | 15999 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 21 2005 12:00AM |
| Updated: | Dec 21 2005 12:00AM |
| Credit: | Discovered by c.y. wang <[email protected]>. |
| Vulnerable: |
RARLAB WinRar 3.51 |
| Not Vulnerable: | |
Discussion
RARLAB WinRAR File Name Potential Buffer Overflow Vulnerability
A client-side buffer overflow vulnerability has been reported in the file name processing functionality of WinRAR.
A remote attacker may supply malicious files to a user to be compressed by WinRAR to exploit this issue. A remote compromise is also possible if the application employs the same routines for decompression, however, this is entirely conjecture and has not been confirmed.
WinRAR 3.51 is reportedly vulnerable. Other versions may be affected as well.
A client-side buffer overflow vulnerability has been reported in the file name processing functionality of WinRAR.
A remote attacker may supply malicious files to a user to be compressed by WinRAR to exploit this issue. A remote compromise is also possible if the application employs the same routines for decompression, however, this is entirely conjecture and has not been confirmed.
WinRAR 3.51 is reportedly vulnerable. Other versions may be affected as well.
Exploit / POC
RARLAB WinRAR File Name Potential Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
RARLAB WinRAR File Name Potential Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
RARLAB WinRAR File Name Potential Buffer Overflow Vulnerability
References:
References: