PT-2006-4758 · Winrar · Winrar
Posidron
·
Publicado
2006-07-27
·
Atualizado
2017-10-19
·
CVE-2006-3912
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
WinRAR versions prior to 3.60 beta 8
Description
A stack-based buffer overflow issue exists in the SFX module of WinRAR, allowing an attacker to cause a stack overflow with a specially crafted file. This results in a loss of integrity. The issue occurs when WinRAR fails to properly process archive comments during file extraction.
Recommendations
For versions prior to 3.60 beta 8, update to version 3.60 beta 8 or later to resolve the issue. As a temporary workaround, consider avoiding the extraction of files with potentially malicious archive comments until a patch is applied. Restrict access to the SFX module to minimize the risk of exploitation.
Exploit
Correção
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Winrar