RARLAB WinRAR LHA Filename Handling Buffer Overflow Vulnerability
BID:19043
CVE-2006-3845 |Info
RARLAB WinRAR LHA Filename Handling Buffer Overflow Vulnerability
| Bugtraq ID: | 19043 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2006-3845 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2006 12:00AM |
| Updated: | Nov 02 2007 04:26PM |
| Credit: | Discovered by Ryan Smith. |
| Vulnerable: |
RARLAB WinRar 3.51 RARLAB WinRar 3.50 RARLAB WinRar 3.42 RARLAB WinRar 3.41 RARLAB WinRar 3.40 RARLAB WinRar 3.30 RARLAB WinRar 3.20 RARLAB WinRar 3.11 RARLAB WinRar 3.10 beta 5 RARLAB WinRar 3.10 beta 3 RARLAB WinRar 3.10 beta 3 RARLAB WinRar 3.10 RARLAB WinRar 3.0 .0 RARLAB WinRar 3.0 RARLAB WinRar 3.60 beta 6 RARLAB WinRar 3.60 beta 5 RARLAB WinRar 3.60 beta 4 RARLAB WinRar 3.60 beta 3 RARLAB WinRar 3.60 beta 2 RARLAB WinRar 3.60 beta 1 |
| Not Vulnerable: |
RARLAB WinRar 3.60 beta 7 |
Discussion
RARLAB WinRAR LHA Filename Handling Buffer Overflow Vulnerability
WinRAR is susceptible to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This vulnerability allows attackers to execute arbitrary machine code in the context of the affected application.
Versions of WinRAR from 3.0 to 3.60 beta 6 are vulnerable to this issue.
WinRAR is susceptible to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer.
This vulnerability allows attackers to execute arbitrary machine code in the context of the affected application.
Versions of WinRAR from 3.0 to 3.60 beta 6 are vulnerable to this issue.
Exploit / POC
RARLAB WinRAR LHA Filename Handling Buffer Overflow Vulnerability
This issue is being exploited in the wild by Trojan.Radropper.
The following exploit code is available:
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
This issue is being exploited in the wild by Trojan.Radropper.
The following exploit code is available:
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
RARLAB WinRAR LHA Filename Handling Buffer Overflow Vulnerability
Solution:
The vendor has released WinRAR 3.60 beta 7 to address this issue.
RARLAB WinRar 3.60 beta 6
RARLAB WinRar 3.60 beta 1
RARLAB WinRar 3.60 beta 4
RARLAB WinRar 3.60 beta 2
RARLAB WinRar 3.60 beta 3
RARLAB WinRar 3.60 beta 5
RARLAB WinRar 3.0
RARLAB WinRar 3.0 .0
RARLAB WinRar 3.10
RARLAB WinRar 3.10 beta 5
RARLAB WinRar 3.10 beta 3
RARLAB WinRar 3.10 beta 3
RARLAB WinRar 3.11
RARLAB WinRar 3.20
RARLAB WinRar 3.30
RARLAB WinRar 3.40
RARLAB WinRar 3.41
RARLAB WinRar 3.42
RARLAB WinRar 3.50
RARLAB WinRar 3.51
Solution:
The vendor has released WinRAR 3.60 beta 7 to address this issue.
RARLAB WinRar 3.60 beta 6
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.60 beta 1
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.60 beta 4
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.60 beta 2
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.60 beta 3
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.60 beta 5
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.0
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.0 .0
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.10
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.10 beta 5
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.10 beta 3
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.10 beta 3
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.11
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.20
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.30
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.40
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.41
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.42
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.50
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
RARLAB WinRar 3.51
-
RARLAB wrar36b7.exe
http://www.rarsoft.com/rar/wrar36b7.exe
References
RARLAB WinRAR LHA Filename Handling Buffer Overflow Vulnerability
References:
References:
- Latest changes in WinRAR (RARLAB)
- RARLab�??s WinRAR Local Stack Overflow (Ryan Smith)
- Trojan.Radropper (Symantec)
- Trojan.Radropper Exploits WinRAR Vulnerability (Symantec)
- WinRAR Homepage (WinRAR)