CVE-2022-23596

Related Vulnerabilities: CVE-2022-23596  

Junrar is an open source java RAR archive library. In affected versions A carefully crafted RAR archive can trigger an infinite loop while extracting said archive. The impact depends solely on how the application uses the library, and whether files can be provided by malignant users. The problem is patched in 7.4.1. There are no known workarounds and users are advised to upgrade as soon as possible.

Description

The MITRE CVE dictionary describes this issue as:

Junrar is an open source java RAR archive library. In affected versions A carefully crafted RAR archive can trigger an infinite loop while extracting said archive. The impact depends solely on how the application uses the library, and whether files can be provided by malignant users. The problem is patched in 7.4.1. There are no known workarounds and users are advised to upgrade as soon as possible.

Additional Information

  • Bugzilla 2049778: CVE-2022-23596 junrar: A carefully crafted RAR archive can trigger an infinite loop while extracting
  • CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
  • FAQ: Frequently asked questions about CVE-2022-23596