CVE-2004-1495: Low severity RARLAB WinRAR vulnerability
Published Dec 31, 2004
·Updated
The Repair Archive command in WinRAR 3.40 allows remote attackers to cause a denial of service (application crash) via a corrupt ZIP archive.
Affected Software
8 affected components
RARLAB WinRAR=3.0.0
RARLAB WinRAR=3.10
RARLAB WinRAR=3.20
RARLAB WinRAR=2.90
RARLAB WinRAR=3.40
RARLAB WinRAR=3.10_beta3
RARLAB WinRAR=3.10_beta5
RARLAB WinRAR=3.11
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 19, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1495?
CVE-2004-1495 has been classified as a low severity vulnerability that can cause a denial of service.
2
How do I fix CVE-2004-1495?
To mitigate CVE-2004-1495, upgrade WinRAR to a version later than 3.40 that resolves this vulnerability.
3
Which versions of WinRAR are affected by CVE-2004-1495?
CVE-2004-1495 affects WinRAR versions 2.90, 3.0.0, 3.10, 3.20, and 3.40.
4
What attack vectors are associated with CVE-2004-1495?
CVE-2004-1495 can be exploited through the handling of a corrupt ZIP archive when using the Repair Archive command.
5
What are the potential consequences of exploiting CVE-2004-1495?
Exploiting CVE-2004-1495 can lead to an application crash, resulting in a denial of service.