WinRAR Archive File Extension Buffer Overrun Vulnerability
BID:6664
Info
WinRAR Archive File Extension Buffer Overrun Vulnerability
| Bugtraq ID: | 6664 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 22 2003 12:00AM |
| Updated: | Jan 22 2003 12:00AM |
| Credit: | The discovery of this vulnerability has been credited to nesumin <[email protected]>. |
| Vulnerable: |
RARLAB WinRar 3.10 RARLAB WinRar 3.0 .0 RARLAB WinRar 2.90 |
| Not Vulnerable: |
RARLAB WinRar 3.11 |
Discussion
WinRAR Archive File Extension Buffer Overrun Vulnerability
A vulnerability has been discovered in WinRAR. The problem occurs when the affected application opens an archive containing a file with an overly long file extension.
It has been reported that it is possible for an attacker to exploit this issue to run arbitrary instructions. Commands executed in this manner would be run with the privileges of the vulnerable program.
A vulnerability has been discovered in WinRAR. The problem occurs when the affected application opens an archive containing a file with an overly long file extension.
It has been reported that it is possible for an attacker to exploit this issue to run arbitrary instructions. Commands executed in this manner would be run with the privileges of the vulnerable program.