WinRAR Vulnerability

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 10892
Joined: Sun Apr 25, 2004 1:05 pm

WinRAR Vulnerability

Post by Tami »

Description:
Secunia Research has discovered two vulnerabilities in WinRAR, which can be exploited by malicious people to compromise a user's system.

1) A format string error exists when displaying a diagnostic error message that informs the user of an invalid filename in an UUE/XXE encoded file. This can be exploited to execute arbitrary code when a malicious UUE/XXE file is decoded.

2) A boundary error in UNACEV2.DLL can be exploited to cause a stack-based buffer overflow. This allows arbitrary code execution when a malicious ACE archive containing a file with an overly long file name is extracted.

[url=\"http://secunia.com/advisories/16973/\"]Full Story[/url]
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”