9.1
CVSSv3

CVE-2017-14122

Published: 03/09/2017 Updated: 25/02/2021
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rarlab unrar 0.0.1

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #874060 unrar-free: CVE-2017-14122: stack overread vulnerability Package: src:unrar-free; Maintainer for src:unrar-free is Ying-Chun Liu (PaulLiu) <paulliu@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 2 Sep 2017 15:21:04 UTC Severity: grave Tags: security, up ...
Debian Bug report logs - #874061 unrar-free: CVE-2017-14121: null pointer dereference Package: src:unrar-free; Maintainer for src:unrar-free is Ying-Chun Liu (PaulLiu) <paulliu@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 2 Sep 2017 15:24:02 UTC Severity: grave Tags: security, upstre ...