CVE-2017-12940: Critical severity unrar vulnerability
Published Aug 18, 2017
·Updated
libunrar.a in UnRAR before 5.5.7 has an out-of-bounds read in the EncodeFileName::Decode call within the Archive::ReadHeader15 function.
Affected Software
1 affected component
RARLAB UnRAR<=5.5.6
Event History
Aug 18, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12940?
CVE-2017-12940 has a medium severity rating due to the potential for out-of-bounds reads affecting the integrity of data.
2
How do I fix CVE-2017-12940?
To fix CVE-2017-12940, update the UnRAR software to version 5.5.7 or later.
3
What software is affected by CVE-2017-12940?
CVE-2017-12940 affects versions of UnRAR prior to 5.5.7.
4
Can CVE-2017-12940 be exploited remotely?
CVE-2017-12940 is not likely to be exploited remotely since it typically requires local access to the affected software's functionality.
5
What are the consequences of CVE-2017-12940?
Exploitation of CVE-2017-12940 may lead to application crashes or unexpected behavior due to out-of-bounds reads.