fkie_cve-2008-7144
Vulnerability from fkie_nvd
Published
2009-09-01 16:30
Modified
2025-04-09 00:30
Severity ?
Summary
Multiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to crafted (1) ACE, (2) ARJ, (3) BZ2, (4) CAB, (5) GZ, (6) LHA, (7) RAR, (8) TAR, or (9) ZIP files, as demonstrated by the OUSPG PROTOS GENOME test suite for Archive Formats.
Impacted products
Vendor Product Version
rarlab winrar *
rarlab winrar 2.90
rarlab winrar 3.0.0
rarlab winrar 3.10
rarlab winrar 3.10_beta3
rarlab winrar 3.10_beta5
rarlab winrar 3.11
rarlab winrar 3.20
rarlab winrar 3.30
rarlab winrar 3.40
rarlab winrar 3.41
rarlab winrar 3.42
rarlab winrar 3.50
rarlab winrar 3.51
rarlab winrar 3.60_beta1
rarlab winrar 3.60_beta2
rarlab winrar 3.60_beta3
rarlab winrar 3.60_beta4
rarlab winrar 3.60_beta5
rarlab winrar 3.60_beta6
rarlab winrar 3.60_beta7
rarlab winrar 3.60_beta8
rarlab winrar 3.61
rarlab winrar 3.62
rarlab winrar 3.70_beta1
rarlab winrar 3.70_beta2
rarlab winrar 3.70_beta3
rarlab winrar 3.70_beta4
rarlab winrar 3.70_beta5
rarlab winrar 3.70_beta6
rarlab winrar 3.70_beta7
rarlab winrar 3.70_beta8



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "0F37E494-C901-414A-9F61-BA2109E6E4EB",
              "versionEndIncluding": "3.70",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:2.90:*:*:*:*:*:*:*",
              "matchCriteriaId": "0FFE81D1-EE81-415D-ACE0-F97AF38BE007",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.0.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "53BDA79B-B1CC-479C-A1DA-41DDDE098EDB",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.10:*:*:*:*:*:*:*",
              "matchCriteriaId": "16A1E0B7-020F-4110-9603-58CA8CEB7581",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.10_beta3:*:*:*:*:*:*:*",
              "matchCriteriaId": "AE627C32-9F4B-4D36-AC4B-5D01A47BFD88",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.10_beta5:*:*:*:*:*:*:*",
              "matchCriteriaId": "3366C2D1-F30A-413B-94A2-7DBDACC083EE",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.11:*:*:*:*:*:*:*",
              "matchCriteriaId": "8585089C-A6B5-4BFE-BEA3-133B94F24F72",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.20:*:*:*:*:*:*:*",
              "matchCriteriaId": "C1011521-AEF2-40EB-B671-66B20FF01CC5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.30:*:*:*:*:*:*:*",
              "matchCriteriaId": "B73F9019-EA47-4962-B080-C65ED42000F1",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.40:*:*:*:*:*:*:*",
              "matchCriteriaId": "9843D850-DC4C-49D5-AAEB-EF75FB54F08C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.41:*:*:*:*:*:*:*",
              "matchCriteriaId": "2C9B3100-2223-4201-AE29-B4A4EAFF2595",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.42:*:*:*:*:*:*:*",
              "matchCriteriaId": "7F95B556-A1B4-4AEF-8223-5ED44819515D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.50:*:*:*:*:*:*:*",
              "matchCriteriaId": "C89BC32A-6D3B-4B83-BD49-856233EEF51C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.51:*:*:*:*:*:*:*",
              "matchCriteriaId": "F5611BDE-8CB6-4FCE-BB12-D16BF60BCE64",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.60_beta1:*:*:*:*:*:*:*",
              "matchCriteriaId": "769CCD65-7409-4685-A228-AE69BEBA5795",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.60_beta2:*:*:*:*:*:*:*",
              "matchCriteriaId": "2229C927-EB0A-4EE4-95FB-7F7EEAA0E5C2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.60_beta3:*:*:*:*:*:*:*",
              "matchCriteriaId": "D721A91B-17D8-4AAF-AC2E-1D9ABEBC39B7",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.60_beta4:*:*:*:*:*:*:*",
              "matchCriteriaId": "F097ED7F-E004-4163-AE7D-0EA89517709C",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.60_beta5:*:*:*:*:*:*:*",
              "matchCriteriaId": "9C152F70-47A9-466F-8299-4A9C36540A44",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.60_beta6:*:*:*:*:*:*:*",
              "matchCriteriaId": "A1860DC9-69C8-4464-A15F-1BF38A2845A6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.60_beta7:*:*:*:*:*:*:*",
              "matchCriteriaId": "25F16922-1BA6-4CDC-B2B3-0E68C13AD815",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.60_beta8:*:*:*:*:*:*:*",
              "matchCriteriaId": "8C71933B-40E9-459C-84D4-B6E90DD7C2C4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.61:*:*:*:*:*:*:*",
              "matchCriteriaId": "56569258-AAA1-4C61-A9C2-C1F310BC710E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.62:*:*:*:*:*:*:*",
              "matchCriteriaId": "2EB470C6-902C-4836-BC31-16532FD1E5C6",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.70_beta1:*:*:*:*:*:*:*",
              "matchCriteriaId": "A941C7F1-8577-4CE1-9852-B2A4C06F23A4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.70_beta2:*:*:*:*:*:*:*",
              "matchCriteriaId": "2821BC83-1A0C-4071-93F7-9B0ADB503038",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.70_beta3:*:*:*:*:*:*:*",
              "matchCriteriaId": "BD80CDF8-4FEA-4B72-BEEF-3E645B4059F4",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.70_beta4:*:*:*:*:*:*:*",
              "matchCriteriaId": "A9EAA3B3-7AA5-4429-9D2F-27DA958513F5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.70_beta5:*:*:*:*:*:*:*",
              "matchCriteriaId": "3337C986-BA06-4A2F-B0A2-A4E128A36214",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.70_beta6:*:*:*:*:*:*:*",
              "matchCriteriaId": "10D394F7-4674-461C-BFB4-F4FD6B73F3EE",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.70_beta7:*:*:*:*:*:*:*",
              "matchCriteriaId": "CCC6E995-0B48-4F52-9516-E07C31220978",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:rarlab:winrar:3.70_beta8:*:*:*:*:*:*:*",
              "matchCriteriaId": "EFA1E9B1-C55F-4EB6-A086-6C077C8713EE",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple unspecified vulnerabilities in RARLAB WinRAR before 3.71 have unknown impact and attack vectors related to crafted (1) ACE, (2) ARJ, (3) BZ2, (4) CAB, (5) GZ, (6) LHA, (7) RAR, (8) TAR, or (9) ZIP files, as demonstrated by the OUSPG PROTOS GENOME test suite for Archive Formats."
    },
    {
      "lang": "es",
      "value": "M\u00faltiples vulnerabilidad no especificadas en RARLAB WinRAR anterior v3.71 tienen impacto desconocido y vectores atacados relacionados con la manipulaci\u00f3n de ficheros (1) ACE, (2) ARJ, (3) BZ2, (4) CAB, (5) GZ, (6) LHA, (7) RAR, (8) TAR, o (9) ZIP, como se ha demostrado mediante la suite para el testeo de formatos de archivo PROTOS GENOME."
    }
  ],
  "id": "CVE-2008-7144",
  "lastModified": "2025-04-09T00:30:58.490",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "HIGH",
        "cvssData": {
          "accessComplexity": "LOW",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "COMPLETE",
          "baseScore": 10.0,
          "confidentialityImpact": "COMPLETE",
          "integrityImpact": "COMPLETE",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "version": "2.0"
        },
        "exploitabilityScore": 10.0,
        "impactScore": 10.0,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": false,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ]
  },
  "published": "2009-09-01T16:30:00.563",
  "references": [
    {
      "source": "cve@mitre.org",
      "url": "http://osvdb.org/43439"
    },
    {
      "source": "cve@mitre.org",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/29407"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/"
    },
    {
      "source": "cve@mitre.org",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "url": "http://www.vupen.com/english/advisories/2008/0916/references"
    },
    {
      "source": "cve@mitre.org",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41251"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://osvdb.org/43439"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Vendor Advisory"
      ],
      "url": "http://secunia.com/advisories/29407"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.cert.fi/haavoittuvuudet/joint-advisory-archive-formats.html"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.ee.oulu.fi/research/ouspg/protos/testing/c10/archive/"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "url": "http://www.vupen.com/english/advisories/2008/0916/references"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41251"
    }
  ],
  "sourceIdentifier": "cve@mitre.org",
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…