CVE-2005-3263: Buffer Overflow
Published Oct 20, 2005
·Updated
Stack-based buffer overflow in UNACEV2.DLL for RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via an ACE archive containing a file with a long name.
Affected Software
11 affected components
RARLAB WinRAR=2.90
RARLAB WinRAR=3.0.0
RARLAB WinRAR=3.10
RARLAB WinRAR=3.10_beta3
RARLAB WinRAR=3.10_beta5
RARLAB WinRAR=3.11
RARLAB WinRAR=3.20
RARLAB WinRAR=3.40
RARLAB WinRAR=3.41
RARLAB WinRAR=3.42
RARLAB WinRAR=3.50
Remediation
Patch Available
Patch Available
Patch Available
Event History
Oct 20, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3263?
CVE-2005-3263 is considered a high severity vulnerability due to the potential for remote code execution.
2
How do I fix CVE-2005-3263?
To fix CVE-2005-3263, upgrade to a version of WinRAR that is above 3.50.
3
Which versions of WinRAR are affected by CVE-2005-3263?
CVE-2005-3263 affects WinRAR versions from 2.90 through 3.50.
4
What type of vulnerability is CVE-2005-3263?
CVE-2005-3263 is a stack-based buffer overflow vulnerability.
5
Can CVE-2005-3263 be exploited remotely?
Yes, CVE-2005-3263 can be exploited remotely via specially crafted ACE archive files.