Retired: RARLAB WinRAR Self-Extracting Archive Buffer Overflow Vulnerability
BID:18851
Info
Retired: RARLAB WinRAR Self-Extracting Archive Buffer Overflow Vulnerability
| Bugtraq ID: | 18851 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2006 12:00AM |
| Updated: | Jul 06 2006 08:24PM |
| Credit: | Discovered by posidron. |
| Vulnerable: |
RARLAB WinRar 3.51 RARLAB WinRar 3.50 RARLAB WinRar 3.42 RARLAB WinRar 3.41 RARLAB WinRar 3.40 RARLAB WinRar 3.30 RARLAB WinRar 3.20 RARLAB WinRar 3.11 RARLAB WinRar 3.10 beta 5 RARLAB WinRar 3.10 beta 3 RARLAB WinRar 3.10 beta 3 RARLAB WinRar 3.10 RARLAB WinRar 3.0 .0 RARLAB WinRar 3.0 RARLAB WinRar 3.60 |
| Not Vulnerable: | |
Discussion
Retired: RARLAB WinRAR Self-Extracting Archive Buffer Overflow Vulnerability
A client-side buffer overflow vulnerability exists in WinRAR.
A remote attacker may supply malicious self-extracting archives to a user to be processed by WinRAR to exploit this issue.
A successful attack may result in a remote compromise in the context of the vulnerable user.
WinRAR 3.60 and prior versions are affected.
Further reports indicate that the vulnerability lies in the code embedded in self-extracting archives, therefore this issue requires that users directly execute malicious EXE files. As users are already executing attacker-provided executable files, nothing extra is gained by this vulnerability. This BID is therefore retired.
A client-side buffer overflow vulnerability exists in WinRAR.
A remote attacker may supply malicious self-extracting archives to a user to be processed by WinRAR to exploit this issue.
A successful attack may result in a remote compromise in the context of the vulnerable user.
WinRAR 3.60 and prior versions are affected.
Further reports indicate that the vulnerability lies in the code embedded in self-extracting archives, therefore this issue requires that users directly execute malicious EXE files. As users are already executing attacker-provided executable files, nothing extra is gained by this vulnerability. This BID is therefore retired.
Exploit / POC
Retired: RARLAB WinRAR Self-Extracting Archive Buffer Overflow Vulnerability
Exploit code is available.
Exploit code is available.
Solution / Fix
Retired: RARLAB WinRAR Self-Extracting Archive Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Retired: RARLAB WinRAR Self-Extracting Archive Buffer Overflow Vulnerability
References:
References:
- WinRAR - Stack Overflows in SelF - eXtracting Archives (posidron)
- WinRAR Homepage (WinRAR)