Title : RARLabs unRAR Password Prompt Handling Client-Side Buffer Overflow Vulnerability VUPEN ID : VUPEN/ADV-2007-0523 CVE ID : CVE-2007-0855
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-02-08
Technical Description
A vulnerability has been identified in RARLabs unRAR, which could be exploited by attackers to execute arbitrary commands. This issue is due to a buffer overflow error when processing specially crafted password protected archives via the command line, which could be exploited by attackers to compromise a vulnerable system by tricking a user to open a malicious archive by responding to the prompt asking for the password.