CVE-2019-25477: RAR Password Recovery 1.80 Denial of Service Buffer Overflow
RAR Password Recovery 1.80 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload in the registration dialog. Attackers can craft a malicious input string exceeding 6000 bytes and paste it into the User Name and Registration Code field to trigger an application crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25477?
CVE-2019-25477 is classified as a high severity vulnerability due to its potential to cause a denial of service attack.
How do I fix CVE-2019-25477?
To fix CVE-2019-25477, upgrade RAR Password Recovery to the latest version that addresses the buffer overflow vulnerability.
What versions of RAR Password Recovery are affected by CVE-2019-25477?
CVE-2019-25477 specifically affects RAR Password Recovery version 1.80.
What type of vulnerability is CVE-2019-25477?
CVE-2019-25477 is a buffer overflow vulnerability that can lead to a denial of service.
Can CVE-2019-25477 be exploited remotely?
No, CVE-2019-25477 requires local access to exploit the vulnerability.