6.8
CVSSv2

CVE-2017-11190

Published: 12/07/2017 Updated: 21/07/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

unrarlib.c in unrar-free 0.0.1, when _DEBUG_LOG mode is enabled, might allow remote malicious users to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via an RAR archive containing a long filename.

Vulnerable Product Search on Vulmon Subscribe to Product

rarzilla unrar-free 0.0.1

Vendor Advisories

Debian Bug report logs - #995065 unrar-free: CVE-2017-11190 fix Package: unrar-free; Maintainer for unrar-free is Ying-Chun Liu (PaulLiu) <paulliu@debianorg>; Source for unrar-free is src:unrar-free (PTS, buildd, popcon) Reported by: Bastian Germann <bastiangermann@fishpostde> Date: Sat, 25 Sep 2021 15:09:04 UTC S ...