Integer overflow in UnRar - CVE-2012-6706
Published: September 25, 2017 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow when processing .rar archives in unrar 5.5.4. A remote unauthenticated attacker can create a specially crafted archive, trigger memory corruption and execute arbitrary code on the target system.
Affected software
Gentoo Linux
Arch Linux
Amazon Linux AMI
Fedora
SUSE Linux
Opensuse
clamav (Alpine package)
clamav
How to mitigate CVE-2012-6706
clamav - addressed in versions 0.99.4-1.el6, 0.99.4-1.el7, 0.99.4-1.fc26, 0.99.4-1.fc27
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Gentoo update for RAR, UnRAR
- Gentoo update for RAR and UnRAR
- Gentoo update for Kodi
- SUSE Linux update for unrar
- SUSE Linux update for clamav
- OpenSUSE Linux update for clamav
- SUSE Linux update for unrar
- Arch Linux update for clamav
- Amazon Linux AMI update for clamav
- SUSE Linux update for clamav
- SUSE Linux update for clamav
- Gentoo update for ClamAV
- OpenSUSE Linux update for clamav
- Integer overflow in clamav (Alpine package)
- Fedora EPEL 6 update for clamav
- Fedora EPEL 7 update for clamav
- Fedora 27 update for clamav
- Fedora 26 update for clamav