Lucene search

K
cveMitreCVE-2004-1254
HistoryJan 10, 2005 - 5:00 a.m.

CVE-2004-1254

2005-01-1005:00:00
mitre
web.nvd.nist.gov
29
winrar
vulnerability
remote code execution
zip file
long filename

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.6

Confidence

High

EPSS

0.027

Percentile

90.6%

WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.

Affected configurations

Nvd
Node
rarlabwinrarMatch3.0.0
OR
rarlabwinrarMatch3.10
OR
rarlabwinrarMatch3.10_beta3
OR
rarlabwinrarMatch3.10_beta5
OR
rarlabwinrarMatch3.11
OR
rarlabwinrarMatch3.20
OR
rarlabwinrarMatch3.40
OR
rarlabwinrarMatch3.41
VendorProductVersionCPE
rarlabwinrar3.0.0cpe:2.3:a:rarlab:winrar:3.0.0:*:*:*:*:*:*:*
rarlabwinrar3.10cpe:2.3:a:rarlab:winrar:3.10:*:*:*:*:*:*:*
rarlabwinrar3.10_beta3cpe:2.3:a:rarlab:winrar:3.10_beta3:*:*:*:*:*:*:*
rarlabwinrar3.10_beta5cpe:2.3:a:rarlab:winrar:3.10_beta5:*:*:*:*:*:*:*
rarlabwinrar3.11cpe:2.3:a:rarlab:winrar:3.11:*:*:*:*:*:*:*
rarlabwinrar3.20cpe:2.3:a:rarlab:winrar:3.20:*:*:*:*:*:*:*
rarlabwinrar3.40cpe:2.3:a:rarlab:winrar:3.40:*:*:*:*:*:*:*
rarlabwinrar3.41cpe:2.3:a:rarlab:winrar:3.41:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.6

Confidence

High

EPSS

0.027

Percentile

90.6%

Related for CVE-2004-1254