9.3
CVSSv2

CVE-2006-3845

Published: 25/07/2006 Updated: 20/07/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 up to and including 3.60 beta 6 allows remote malicious users to execute arbitrary code via a long filename in a LHA archive.

Vulnerable Product Search on Vulmon Subscribe to Product

rarlab winrar 3.10_beta5

rarlab winrar 3.11

rarlab winrar 3.51

rarlab winrar 3.60_beta1

rarlab winrar 3.20

rarlab winrar 3.30

rarlab winrar 3.60_beta2

rarlab winrar 3.60_beta3

rarlab winrar 3.0.0

rarlab winrar 3.10

rarlab winrar 3.10_beta3

rarlab winrar 3.42

rarlab winrar 3.50

rarlab winrar 3.60_beta6

rarlab winrar 3.40

rarlab winrar 3.41

rarlab winrar 3.60_beta4

rarlab winrar 3.60_beta5

Exploits

source: wwwsecurityfocuscom/bid/19043/info WinRAR is susceptible to a remote buffer-overflow vulnerability because it fails to properly bounds-check user-supplied input before copying it to an insufficiently sized memory buffer This vulnerability allows attackers to execute arbitrary machine code in the context of the affected applicati ...