Remote Code Execution Vulnerability in WinRAR by Rarlab
CVE-2004-1254

Currently unrated

Key Information:

Vendor
Rarlab
Status
Vendor
CVE Published:
10 January 2005

Summary

WinRAR versions 3.40 and earlier are susceptible to a vulnerability that allows remote attackers to execute arbitrary code. This issue arises when processing ZIP files containing files with excessively long filenames, potentially causing an integer overflow that may lead to a buffer overflow. Attackers can exploit this flaw to gain unauthorized access to systems, highlighting the importance of keeping software updated and implementing robust security measures.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2004-1254 : Remote Code Execution Vulnerability in WinRAR by Rarlab | SecurityVulnerability.io