Junrar vulnerable to infinite loop via extracting carefully crafted RAR archive
Description
Reviewed
Jan 31, 2022
Published to the GitHub Advisory Database
Feb 1, 2022
Published by the National Vulnerability Database
Feb 1, 2022
Last updated
Jan 30, 2023
Impact
A carefully crafted RAR archive can trigger an infinite loop while extracting said archive. The impact depends solely on how the application uses the library, and whether files can be provided by malignant users.
Patches
The problem is partially patched in 7.4.1
Workarounds
None
References
junrar/junrar#73
junrar/junrar#81
References