CVE-2017-20006: Buffer Overflow
Published Jul 1, 2021
·Updated
UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile).
Affected Software
3 affected components
RARLAB UnRAR=5.6.1.2
RARLAB UnRAR=5.6.1.3
Linux Linux kernel
Remediation
Patch Available
Event History
Jul 1, 2021
CVE Published
via MITRE·02:54 AM
Data Sourced
via MITRE·02:54 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of UnRAR?
The vulnerability ID of UnRAR is CVE-2017-20006.
2
What is the severity rating of CVE-2017-20006?
The severity rating of CVE-2017-20006 is high.
3
What is the affected version of UnRAR?
The affected version of UnRAR is 5.6.1.2 and 5.6.1.3.
4
How does the vulnerability manifest in UnRAR?
The vulnerability manifests as a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile).
5
Is the Linux kernel affected by this vulnerability?
No, the Linux kernel is not affected by this vulnerability.
6
Are there any known fixes or patches for this vulnerability?
Yes, a fix for this vulnerability has been implemented in the following commit: https://github.com/aawc/unrar/commit/0ff832d31470471803b175cfff4e40c1b08ee779