Input validation error in WinRAR - CVE-2024–36052

 

Input validation error in WinRAR - CVE-2024–36052

Published: June 13, 2024


Vulnerability identifier: #VU92078
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024–36052
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service or spoofing attack.

The vulnerability exists due to insufficient validation of ANSI escape sequences within the CLI interface. A remote attacker can pass specially crafted input via CLI and spoof the archive output or perform a denial of service (DoS) attack.

Note, the vulnerability affects Windows installations only.


Affected software

WinRAR
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
unrar-debugsource
libunrar5_6_1
libunrar-devel
unrar-debuginfo
libunrar5_6_1-debuginfo
unrar

How to mitigate CVE-2024–36052

Install updates from vendor's website.

WinRAR - update to 7.00
unrar-debugsource - update to 5.6.1-4.11.1
libunrar5_6_1 - update to 5.6.1-4.11.1
libunrar-devel - update to 5.6.1-4.11.1
unrar-debuginfo - update to 5.6.1-4.11.1
libunrar5_6_1-debuginfo - update to 5.6.1-4.11.1
unrar - update to 5.6.1-4.11.1

External References

Related Security Bulletins