The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this may be the same as one of the several test cases in the CVE-2017-11189 references.
A NULL pointer dereference occurs when the application dereferences a pointer that it expects to be valid, but is NULL, typically causing a crash or exit.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Unrar | Rarlab | 0.0.1 (including) | 0.0.1 (including) |
Unrar-free | Ubuntu | artful | * |
Unrar-free | Ubuntu | trusty | * |
Unrar-free | Ubuntu | trusty/esm | * |
Unrar-free | Ubuntu | upstream | * |
Unrar-free | Ubuntu | xenial | * |
Unrar-free | Ubuntu | zesty | * |