Multiple vulnerabilities in UnRar



Published: 2017-09-26
Risk High
Patch available YES
Number of vulnerabilities 3
CVE-ID CVE-2017-12940
CVE-2017-12941
CVE-2017-12942
CWE-ID CWE-125
CWE-119
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
UnRar
Client/Desktop applications / Software for archiving

Vendor RARLAB

Security Bulletin

This security bulletin contains information about 3 vulnerabilities.

1) Out-of-bounds read

EUVDB-ID: #VU8603

Risk: Low

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2017-12940

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a remote attacker to crash the affected application.

The vulnerability exists due to out-pf-bounds read in libunrar.a in UnRAR before 5.5.7 in the EncodeFileName::Decode call within the Archive::ReadHeader15 function. A remote attacker can create a specially crafted archive and crash the affected application.

Mitigation

Update to version 5.5.7.

Vulnerable software versions

UnRar: 5.5.6

External links

http://seclists.org/oss-sec/2017/q3/290


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to trick the victim to open a a specially crafted archive.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Out-of-bounds read

EUVDB-ID: #VU8604

Risk: Low

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2017-12941

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a remote attacker to crash the affected application.

The vulnerability exists due to out-of-bounds read in libunrar.a in UnRAR before 5.5.7 in the Unpack::Unpack20 function. A remote attacker can create a specially crafted archive and crash the affected application.

Mitigation

Update to version 5.5.7.

Vulnerable software versions

UnRar: 5.5.6

External links

http://seclists.org/oss-sec/2017/q3/290


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to trick the victim to open a a specially crafted archive.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Buffer overflow

EUVDB-ID: #VU8605

Risk: High

CVSSv3.1: 8.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]

CVE-ID: CVE-2017-12942

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error when processing archives in in the Unpack::LongLZ function in libunrar.a in UnRAR before 5.5.7. A remote unauthenticated attacker can create a specially crafted archive, trick the victim into opening it an execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update to version 5.5.7.

Vulnerable software versions

UnRar: 5.5.6

External links

http://seclists.org/oss-sec/2017/q3/290


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to trick the victim to open a a specially crafted archive.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###