RARLAB UnRAR '.rar' File Buffer Overflow Vulnerability
BID:49041
Info
RARLAB UnRAR '.rar' File Buffer Overflow Vulnerability
| Bugtraq ID: | 49041 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2011 12:00AM |
| Updated: | Aug 05 2011 12:00AM |
| Credit: | ZadYree |
| Vulnerable: |
RARLAB UnRar 3.26 RARLAB UnRar 3.20 RARLAB UnRar 3.6 RARLAB UnRar 3.4 RARLAB UnRar 3.3.6 RARLAB UnRar 3.2.3 RARLAB UnRar 3.1 RARLAB UnRar 3.0 RARLAB UnRar 3.9.3 RARLAB UnRar 3.61 RARLAB UnRar 3.60 |
| Not Vulnerable: | |
Discussion
RARLAB UnRAR '.rar' File Buffer Overflow Vulnerability
UnRAR is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
UnRAR versions 3.9.3 and prior are vulnerable.
UnRAR is prone to a stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied input.
Attackers may leverage this issue to execute arbitrary code in the context of the application. Failed attacks will cause denial-of-service conditions.
UnRAR versions 3.9.3 and prior are vulnerable.
Exploit / POC
RARLAB UnRAR '.rar' File Buffer Overflow Vulnerability
The following proof-of-concept code is available:
The following proof-of-concept code is available:
Solution / Fix
RARLAB UnRAR '.rar' File Buffer Overflow Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].