CVE-2004-1254
WinRAR 3.40 - Remote Code Execution via ZIP File with Long Filename
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1254. PoCs published by Vafa Khoshaein.
AI-analyzed exploit summary This exploit generates a malformed ZIP file that triggers a buffer overflow in WinRAR 3.40 when attempting to delete a file within the archive. The PoC creates a ZIP file with an overly long filename to overflow a buffer and overwrite EIP.
Description
WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.
Exploits (1)
This exploit generates a malformed ZIP file that triggers a buffer overflow in WinRAR 3.40 when attempting to delete a file within the archive. The PoC creates a ZIP file with an overly long filename to overflow a buffer and overwrite EIP.