Stack-based Buffer Over-read Vulnerability in unrar by RARLAB
CVE-2017-14122
9.1CRITICAL
What is CVE-2017-14122?
The unrar-free software version 0.0.1, also known as unrar-gpl, is affected by a stack-based buffer over-read vulnerability. This flaw exists in the unrarlib.c file, specifically associated with the handling of ExtrFile and stricomp, which could potentially allow an attacker to exploit memory and expose sensitive data.