Format string vulnerability in RARLAB WinRAR 2.90 through 3.50 allows remote attackers to execute arbitrary code via format string specifiers in a UUE/XXE file, which are not properly handled when WinRAR displays diagnostic errors related to an invalid filename.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/15062 | vdb entry patch |
http://secunia.com/advisories/16973/ | third party advisory patch vendor advisory |
http://www.rarlabs.com/rarnew.htm | |
http://secunia.com/secunia_research/2005-53/advisory/ | patch vendor advisory |