CVE-2017-14122: Critical severity unrar vulnerability
Published Sep 3, 2017
·Updated
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a stack-based buffer over-read in unrarlib.c, related to ExtrFile and stricomp.
Affected Software
2 affected components
RARLAB UnRAR=0.0.1
Debian Debian Linux=9.0
Event History
Sep 3, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14122?
CVE-2017-14122 has a high severity rating due to its potential to cause a stack-based buffer over-read.
2
How do I fix CVE-2017-14122?
To fix CVE-2017-14122, update to a version of UnRAR that has addressed this vulnerability.
3
What versions of UnRAR are affected by CVE-2017-14122?
CVE-2017-14122 affects UnRAR version 0.0.1.
4
Is CVE-2017-14122 present in Debian Linux?
Yes, CVE-2017-14122 is present in Debian Linux version 9.0 when using the affected version of UnRAR.
5
What type of vulnerability is CVE-2017-14122?
CVE-2017-14122 is classified as a stack-based buffer over-read vulnerability.