frsirt.com
http://www.frsirt.com/exploits/20041217.Winrar.c.php CVE-2004-1254
WinRAR 3.4.1 - Corrupt '.ZIP' File
Record summary
CVE-2004-1254 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBWinRAR 3.4.1 - Corrupt '.ZIP' FileExploitDB exploitby Vafa KhoshaeinNot analyzed1 file
References
3winrar-zip-file-bo(18569)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/18569 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1254