CVE Vulnerabilities

CVE-2005-3262

Published: Oct 20, 2005 | Modified: Sep 10, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.

Affected Software

Name Vendor Start Version End Version
Winrar Rarlab 2.90 (including) 2.90 (including)
Winrar Rarlab 3.0.0 (including) 3.0.0 (including)
Winrar Rarlab 3.10 (including) 3.10 (including)
Winrar Rarlab 3.10_beta3 (including) 3.10_beta3 (including)
Winrar Rarlab 3.10_beta5 (including) 3.10_beta5 (including)
Winrar Rarlab 3.11 (including) 3.11 (including)
Winrar Rarlab 3.20 (including) 3.20 (including)
Winrar Rarlab 3.40 (including) 3.40 (including)
Winrar Rarlab 3.41 (including) 3.41 (including)
Winrar Rarlab 3.42 (including) 3.42 (including)
Winrar Rarlab 3.50 (including) 3.50 (including)

References