Input validation error in UnRar - CVE-2024-33899

 

Input validation error in UnRar - CVE-2024-33899

Published: June 13, 2024


Vulnerability identifier: #VU92077
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-33899
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service or spoofing attack.

The vulnerability exists due to insufficient validation of ANSI escape sequences within the CLI interface. A remote attacker can pass specially crafted input via CLI and spoof the archive output or perform a denial of service (DoS) attack.

Note, the vulnerability affects Linux and Unix installations only.


Affected software

UnRar
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Ubuntu
IBM OmniFind Text Search Server for DB2 for i
unrar-debugsource
libunrar5_6_1
libunrar-devel
unrar-debuginfo
libunrar5_6_1-debuginfo
unrar
libunrar5 (Ubuntu package)
unrar (Ubuntu package)

How to mitigate CVE-2024-33899

Install updates from vendor's website.

UnRar - update to 7.00
unrar-debugsource - update to 5.6.1-4.11.1
libunrar5_6_1 - update to 5.6.1-4.11.1
libunrar-devel - update to 5.6.1-4.11.1
unrar-debuginfo - update to 5.6.1-4.11.1
libunrar5_6_1-debuginfo - update to 5.6.1-4.11.1
unrar - update to 5.6.1-4.11.1
libunrar5 (Ubuntu package) - addressed in versions 1:5.6.6-2ubuntu0.1, 1:6.1.5-1ubuntu0.1
unrar (Ubuntu package) - addressed in versions 1:5.6.6-2ubuntu0.1, 1:6.1.5-1ubuntu0.1

External References

Related Security Bulletins