RARLAB WinRAR File Extension Spoofing Vulnerability
BID:66383
Info
RARLAB WinRAR File Extension Spoofing Vulnerability
| Bugtraq ID: | 66383 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 23 2014 12:00AM |
| Updated: | Mar 23 2014 12:00AM |
| Credit: | Danor Cohen |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
RARLAB WinRAR File Extension Spoofing Vulnerability
RARLAB WinRAR is prone to a security vulnerability that may allow attackers to conduct spoofing attacks.
An attacker may leverage this issue to spoof downloaded filenames to unsuspecting users, Other attacks are also possible.
RARLAB WinRAR 4.20 is vulnerable; other versions may also be affected.
RARLAB WinRAR is prone to a security vulnerability that may allow attackers to conduct spoofing attacks.
An attacker may leverage this issue to spoof downloaded filenames to unsuspecting users, Other attacks are also possible.
RARLAB WinRAR 4.20 is vulnerable; other versions may also be affected.
Exploit / POC
RARLAB WinRAR File Extension Spoofing Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
Solution / Fix
RARLAB WinRAR File Extension Spoofing Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].