SecureScoutLogo.jpg
WinRAR UnRAR Password Prompt Buffer Overflow Vulnerability (Remote File Checking)



Go to Vulnerabilities List


General Info


TC: 16414
Description: A vulnerability has been reported in RARLabs UnRAR, which can be exploited by malicious people to compromise a user's system.

The vulnerability is caused due to a boundary error when processing password-protected archives using the UnRAR command line utility. This can be exploited to cause a stack-based buffer overflow via a specially crafted password-protected archive.

Successful exploitation requires that the user is e.g. tricked into opening a password-protected archive and respond to the password prompt.

The vulnerability is reported in version 3.60 for Linux and 3.61 for Windows. Other versions may also be affected.

The vendor has issued version 3.70 beta release to fix the issue.
TC Impact: Gather Info



Specific Operations and Actions:


Vulnerability Publication: February 8, 2007
Advisory Copyright: Discovered by an anonymous person and reported via iDefense Labs
Summary: A vulnerability has been reported in RARLabs UnRAR, which can be exploited by malicious people to compromise a user's system.
Risk: High
CVSS 2.0 metrics: Access Vector: Network
Access Complexity: High
Authentication: None
Confidentiality Impact: Complete
Integrity Impact: Complete
Availability Impact: Complete
(Approximated from CVSS 1.0 metrics)
CVSS 2.0 Base Score: 8.0 (Approximated)
Vulnerability Impact: Attack
Host Impact: Execution of arbitrary code.
Nature of Remediation: Update the software.
Step required to fix the reported vulnerability:

***** Solution type: Upgrade Software *****

Download and update to at least version 3.70 beta.
See references for more details.



Glossary and References :


References:
Original advisory:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=472

Other references:
http://secunia.com/advisories/24077/

Product Homepage:
http://www.rarlabs.com/

CVE Link: GENERIC-MAP-NOMATCH
CVE Compatible

Glossary: Arbitrary Command Execution
Buffer Overflow
Denial of Service


© 2003-2010 NexantiS Corporation (www.securescout.com)
SecureScout is a trademark of NexantiS
All Rights Reserved
All products names referenced herein are trademarks of their respective companies

SecureScout products are certified:
CVE Compatible
SANS TOP 20 Compatible
CVSS Compatible (Common Vulnerability Scoring System)