CVE-2004-1254: Buffer Overflow
Published Dec 22, 2004
·Updated
WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.
Affected Software
8 affected components
RARLAB WinRAR=3.0.0
RARLAB WinRAR=3.10
RARLAB WinRAR=3.41
RARLAB WinRAR=3.20
RARLAB WinRAR=3.40
RARLAB WinRAR=3.10_beta3
RARLAB WinRAR=3.10_beta5
RARLAB WinRAR=3.11
Event History
Dec 22, 2004
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1254?
CVE-2004-1254 is considered a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix CVE-2004-1254?
To fix CVE-2004-1254, upgrade to the latest version of WinRAR that addresses this vulnerability.
3
Which versions of WinRAR are affected by CVE-2004-1254?
CVE-2004-1254 affects WinRAR versions 3.0.0 through 3.40 and possibly earlier versions.
4
What type of attack does CVE-2004-1254 facilitate?
CVE-2004-1254 facilitates a remote code execution attack via a specially crafted ZIP file.
5
Is CVE-2004-1254 still a relevant threat today?
Despite being discovered in 2004, CVE-2004-1254 could still pose a risk if vulnerable versions of WinRAR are used.