CVE-2017-14121: Null Pointer Dereference
Published Sep 3, 2017
·Updated
The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this may be the same as one of the several test cases in the CVE-2017-11189 references.
Affected Software
2 affected components
RARLAB UnRAR=0.0.1
Debian Debian Linux=9.0
Event History
Sep 3, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14121?
CVE-2017-14121 has a low severity rating due to its nature as a NULL pointer dereference flaw.
2
How do I fix CVE-2017-14121?
To fix CVE-2017-14121, update to a patched version of unrar beyond 0.0.1.
3
Which software is affected by CVE-2017-14121?
CVE-2017-14121 affects unrar version 0.0.1 and Debian GNU/Linux 9.0.
4
What impact does CVE-2017-14121 have on systems?
CVE-2017-14121 can lead to application crashes when processing specially crafted RAR archives.
5
Is CVE-2017-14121 exploitable in the wild?
There have been no confirmed reports of CVE-2017-14121 being actively exploited in the wild.