LWN.net Logo

RAR: format string and buffer overflow

Package(s):rar CVE #(s):
Created:November 14, 2005 Updated:November 16, 2005
Description: Tan Chew Keong reported two vulnerabilities in RAR: a format string error exists when displaying a diagnostic error message that informs the user of an invalid filename in an UUE/XXE encoded file and some boundary errors in the processing of malicious ACE archives can be exploited to cause a buffer overflow.
Alerts:
Gentoo 200511-10 2005-11-13

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds