4.3
CVSSv2

CVE-2017-14121

Published: 03/09/2017 Updated: 18/10/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 384
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this may be the same as one of the several test cases in the CVE-2017-11189 references.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rarlab unrar 0.0.1

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #874060 unrar-free: CVE-2017-14122: stack overread vulnerability Package: src:unrar-free; Maintainer for src:unrar-free is Ying-Chun Liu (PaulLiu) <paulliu@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 2 Sep 2017 15:21:04 UTC Severity: grave Tags: security, up ...
Debian Bug report logs - #874061 unrar-free: CVE-2017-14121: null pointer dereference Package: src:unrar-free; Maintainer for src:unrar-free is Ying-Chun Liu (PaulLiu) <paulliu@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 2 Sep 2017 15:24:02 UTC Severity: grave Tags: security, upstre ...