PT-2005-4076 · Winrar · Winrar

Published

2005-10-20

·

Updated

2008-09-10

·

CVE-2005-3263

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WinRAR versions 2.90 through 3.50
Description The issue is related to a stack-based buffer overflow in the UNACEV2.DLL library of WinRAR, which allows remote attackers to execute arbitrary code. This can be achieved by creating a specially crafted ACE archive that contains a compressed file with an overly long filename. The lack of proper bounds checking in the library results in a buffer overflow, leading to a potential loss of integrity.
Recommendations For WinRAR versions 2.90 through 3.50, consider updating to a version that includes a fix for the buffer overflow issue in the UNACEV2.DLL library. As a temporary workaround, restrict the handling of ACE archives with long filenames to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3263

Affected Products

Winrar