CVE-2007-3726: Medium severity RARLAB UnRAR vulnerability
Integer signedness error in the SETVALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-3726?
CVE-2007-3726 is assessed as a medium severity vulnerability due to its potential for denial of service attacks.
How do I fix CVE-2007-3726?
To fix CVE-2007-3726, update to a patched version of UnRAR or WinRAR that addresses the integer signedness error.
What is the impact of CVE-2007-3726?
The impact of CVE-2007-3726 is a denial of service, causing the application to crash when processing a specially crafted RAR archive.
Which versions are affected by CVE-2007-3726?
CVE-2007-3726 affects unrar version 3.70 beta 3 specifically.
Who is vulnerable to CVE-2007-3726?
Users of WinRAR and RAR for OS X utilizing affected versions of UnRAR are vulnerable to CVE-2007-3726.