CVE-2006-3845: Buffer Overflow
Published Jul 25, 2006
·Updated
Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.
Affected Software
18 affected components
RARLAB WinRAR=3.0.0
RARLAB WinRAR=3.10
RARLAB WinRAR=3.10_beta3
RARLAB WinRAR=3.10_beta5
RARLAB WinRAR=3.11
RARLAB WinRAR=3.20
RARLAB WinRAR=3.30
RARLAB WinRAR=3.40
RARLAB WinRAR=3.41
RARLAB WinRAR=3.42
RARLAB WinRAR=3.50
RARLAB WinRAR=3.51
RARLAB WinRAR=3.60_beta1
RARLAB WinRAR=3.60_beta2
RARLAB WinRAR=3.60_beta3
RARLAB WinRAR=3.60_beta4
RARLAB WinRAR=3.60_beta5
RARLAB WinRAR=3.60_beta6
Remediation
Patch Available
Event History
Jul 25, 2006
CVE Published
11:04 PM
Jul 26, 2006
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-3845?
CVE-2006-3845 is rated as critical due to its potential for remote code execution.
2
How do I fix CVE-2006-3845?
To fix CVE-2006-3845, upgrade to the latest version of WinRAR, as the vulnerability has been patched in subsequent releases.
3
Which versions of WinRAR are affected by CVE-2006-3845?
CVE-2006-3845 affects WinRAR versions 3.00 through 3.60 beta 6.
4
Can CVE-2006-3845 be exploited remotely?
Yes, CVE-2006-3845 can be exploited remotely by sending a specially crafted LHA archive with a long filename.
5
What are the potential consequences of CVE-2006-3845?
The potential consequences of CVE-2006-3845 include arbitrary code execution, which could lead to system compromise.