CVE-2007-3726Unrar vulnerability

5 documents5 sources
Severity
4.3MEDIUMNVD
EPSS
1.0%
top 23.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 12
Latest updateMay 1

Description

Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

NVDrarlab/unrar3.70_beta_3
Debianrarlab/rar< 1:3.7b1-1+3

🔴Vulnerability Details

3
GHSA
GHSA-2w7p-wvwf-625f: Integer signedness error in the SET_VALUE function in rarvm2022-05-01
OSV
CVE-2007-3726: Integer signedness error in the SET_VALUE function in rarvm2007-07-12
CVEList
CVE-2007-3726: Integer signedness error in the SET_VALUE function in rarvm2007-07-12

📋Vendor Advisories

1
Debian
CVE-2007-3726: rar - Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 be...2007
CVE-2007-3726 — Rarlab Unrar vulnerability | cvebase