Input validation error in WinRAR - CVE-2024–36052
Published: June 13, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service or spoofing attack.
The vulnerability exists due to insufficient validation of ANSI escape sequences within the CLI interface. A remote attacker can pass specially crafted input via CLI and spoof the archive output or perform a denial of service (DoS) attack.
Note, the vulnerability affects Windows installations only.
Affected software
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
unrar-debugsource
libunrar5_6_1
libunrar-devel
unrar-debuginfo
libunrar5_6_1-debuginfo
unrar
How to mitigate CVE-2024–36052
unrar-debugsource - update to 5.6.1-4.11.1
libunrar5_6_1 - update to 5.6.1-4.11.1
libunrar-devel - update to 5.6.1-4.11.1
unrar-debuginfo - update to 5.6.1-4.11.1
libunrar5_6_1-debuginfo - update to 5.6.1-4.11.1
unrar - update to 5.6.1-4.11.1