Lucene search

K
redosRedosROS-20240507-01
HistoryMay 07, 2024 - 12:00 a.m.

ROS-20240507-01

2024-05-0700:00:00
redos.red-soft.ru
5
winrar
ansi escape
vulnerability
input data
remote exploitation
denial of service
screen output
unix

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%

Vulnerability of ANSI Escape Sequence Handler component of WinRAR file archiver is related to errors in input data processing.
input data processing errors. Exploitation of the vulnerability could allow an attacker acting remotely,
cause a denial of service or tamper with screen output

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64unrar<= 7.0.7-2UNKNOWN

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

9.0%