Secunia Logo
 
CVE Reference: CVE-2005-3262
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-3262

Description:
Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.

CVE Status:
Candidate

References:

SAID
  Secunia Advisory: SA16973

MISC
  http://secunia.com/secunia_research/2005-53/advisory/

CONFIRM
  http://www.rarlabs.com/rarnew.htm

BID
  15062


Return to the previous page.