Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Retired: RARLAB WinRAR Self-Extracting Archive Buffer Overflow Vulnerability

A client-side buffer overflow vulnerability exists in WinRAR.

A remote attacker may supply malicious self-extracting archives to a user to be processed by WinRAR to exploit this issue.

A successful attack may result in a remote compromise in the context of the vulnerable user.

WinRAR 3.60 and prior versions are affected.

Further reports indicate that the vulnerability lies in the code embedded in self-extracting archives, therefore this issue requires that users directly execute malicious EXE files. As users are already executing attacker-provided executable files, nothing extra is gained by this vulnerability. This BID is therefore retired.







 

Privacy Statement
Copyright 2009, SecurityFocus