#VU8603 Out-of-bounds read in UnRar - CVE-2017-12940
Published: September 25, 2017 / Updated: September 26, 2017
UnRar
RARLAB
Description
The vulnerability allows a remote attacker to crash the affected application.
The vulnerability exists due to out-pf-bounds read in libunrar.a in UnRAR before 5.5.7 in the EncodeFileName::Decode call within the Archive::ReadHeader15 function. A remote attacker can create a specially crafted archive and crash the affected application.