Record summary

CVE-2004-1254 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.

Description

WinRAR 3.40, and possibly earlier versions, allows remote attackers to execute arbitrary code via a ZIP file containing a file with a long filename, possibly causing an integer overflow that leads to a buffer overflow.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBWinRAR 3.4.1 - Corrupt '.ZIP' FileExploitDB exploitby Vafa KhoshaeinNot analyzed1 file
ExploitDB

PoC details

References

3