First published: Tue Jul 25 2006(Updated: )
Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WinRAR | =3.50 | |
WinRAR | =3.0.0 | |
WinRAR | =3.10 | |
WinRAR | =3.51 | |
WinRAR | =3.60_beta3 | |
WinRAR | =3.41 | |
WinRAR | =3.20 | |
WinRAR | =3.42 | |
WinRAR | =3.60_beta2 | |
WinRAR | =3.30 | |
WinRAR | =3.60_beta5 | |
WinRAR | =3.40 | |
WinRAR | =3.10_beta3 | |
WinRAR | =3.60_beta6 | |
WinRAR | =3.60_beta4 | |
WinRAR | =3.10_beta5 | |
WinRAR | =3.60_beta1 | |
WinRAR | =3.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3845 is rated as critical due to its potential for remote code execution.
To fix CVE-2006-3845, upgrade to the latest version of WinRAR, as the vulnerability has been patched in subsequent releases.
CVE-2006-3845 affects WinRAR versions 3.00 through 3.60 beta 6.
Yes, CVE-2006-3845 can be exploited remotely by sending a specially crafted LHA archive with a long filename.
The potential consequences of CVE-2006-3845 include arbitrary code execution, which could lead to system compromise.