CVE-2018-25018: High severity unrar vulnerability
Published Jul 1, 2021
·Updated
UnRAR 5.6.1.7 through 5.7.4 and 6.0.3 has an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext.
Affected Software
3 affected components
RARLAB UnRAR>=5.6.1.7<=5.7.4
RARLAB UnRAR=6.0.3
Linux Linux kernel
Remediation
Patch Available
Event History
Jul 1, 2021
CVE Published
via MITRE·02:54 AM
Data Sourced
via MITRE·02:54 AM
Description
Frequently Asked Questions
1
What is CVE-2018-25018?
CVE-2018-25018 is a vulnerability in UnRAR versions 5.6.1.7 through 5.7.4 and 6.0.3 that allows an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext.
2
How severe is CVE-2018-25018?
CVE-2018-25018 has a severity rating of 7.8 out of 10, which is considered high.
3
Which software versions are affected by CVE-2018-25018?
The affected software versions include UnRAR 5.6.1.7 through 5.7.4 and 6.0.3.
4
How can I fix CVE-2018-25018?
To fix CVE-2018-25018, you should update UnRAR to a version that is not affected by the vulnerability, such as version 6.0.4 or later.
5
Where can I find more information about CVE-2018-25018?
You can find more information about CVE-2018-25018 on the Chromium bug tracker and the OSS-Fuzz vulnerability report.