First published: Thu Jul 01 2021(Updated: )
UnRAR 5.6.1.7 through 5.7.4 and 6.0.3 has an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RARLAB UnRAR | >=5.6.1.7<=5.7.4 | |
RARLAB UnRAR | =6.0.3 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-25018 is a vulnerability in UnRAR versions 5.6.1.7 through 5.7.4 and 6.0.3 that allows an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext.
CVE-2018-25018 has a severity rating of 7.8 out of 10, which is considered high.
The affected software versions include UnRAR 5.6.1.7 through 5.7.4 and 6.0.3.
To fix CVE-2018-25018, you should update UnRAR to a version that is not affected by the vulnerability, such as version 6.0.4 or later.
You can find more information about CVE-2018-25018 on the Chromium bug tracker and the OSS-Fuzz vulnerability report.