First published: Sun Sep 03 2017(Updated: )
The DecodeNumber function in unrarlib.c in unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a NULL pointer dereference flaw triggered by a crafted RAR archive. NOTE: this may be the same as one of the several test cases in the CVE-2017-11189 references.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
UnRAR | =0.0.1 | |
Debian | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14121 has a low severity rating due to its nature as a NULL pointer dereference flaw.
To fix CVE-2017-14121, update to a patched version of unrar beyond 0.0.1.
CVE-2017-14121 affects unrar version 0.0.1 and Debian GNU/Linux 9.0.
CVE-2017-14121 can lead to application crashes when processing specially crafted RAR archives.
There have been no confirmed reports of CVE-2017-14121 being actively exploited in the wild.