Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-36052
HistoryMay 21, 2024 - 12:00 a.m.

CVE-2024-36052

2024-05-2100:00:00
ubuntu.com
ubuntu.com
6
windows
winrar
spoofing
ansi escape sequences

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

7.2 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%

RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen
output via ANSI escape sequences, a different issue than CVE-2024-33899.

Notes

Author Note
alexmurray This CVE is specific to WinRAR on Windows - there is an associated CVE for WinRAR on Linux (aka unrar-nonfree in Ubuntu) in CVE-2024-33899

7.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

7.2 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.0%