Vulnerabilities > CVE-2005-3262 - Remote vulnerability in RARLAB WinRAR

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
rarlab
exploit available

Summary

Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.

Exploit-Db

descriptionRARLAB WinRar 2.90/3.x UUE/XXE Invalid Filename Error Message Format String. CVE-2005-3262 . Dos exploit for linux platform
idEDB-ID:26342
last seen2016-02-03
modified2005-10-11
published2005-10-11
reporterTan Chew Keong
sourcehttps://www.exploit-db.com/download/26342/
titleRARLAB WinRar 2.90/3.x UUE/XXE Invalid Filename Error Message Format String