Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Warning: Critical WinRAR Flaw Affects All Versions Released In Last 19 Years
#1
Information 
It's reported that only in version WinRar 5.70 Beta 1 these critical vulnerabilities has been fixed.

Quote:Quote: CRITICAL VULNERABILITIES HAVE BEEN IMPACTING WINRAR FOR ALMOST 20 YEARS
Over 500 million WinRAR users could have been exposed; update your software as soon as possible
Source: https://www.securitynewspaper.com/2019/0...-20-years/

In German from another source:

Quote:Quote:ACE-Format: Kritische Lücke in WinRAR erst nach 14 Jahren entdeckt
Translate :ACE format: Critical vulnerabilities in WinRAR not discovered until 14 years later
Source: https://www.computerbase.de/2019-02/ace-...ke-winrar/

That shows it's sometimes possible to discover critical vulnerabilities in programs and systems.

Only "sometimes by chance" or issues such vulnerabilities can be detected during intensively analysis.  

Kind regards
[-] The following 3 users say Thank You to darktwilight for this post:
  • Deep900, harlan4096, silversurfer
Reply
#2
[Image: 36597e71c580.png]

Quote:Beware Windows users... a new dangerous remote code execution vulnerability has been discovered in the WinRAR software, affecting hundreds of millions of users worldwide.

Cybersecurity researchers at Check Point have disclosed technical details of a critical vulnerability in WinRAR—a popular Windows file compression application with 500 million users worldwide—that affects all versions of the software released in last 19 years.

The flaw resides in the way an old third-party library, called UNACEV2.DLL, used by the software handled the extraction of files compressed in ACE data compression archive file format.

However, since WinRAR detects the format by the content of the file and not by the extension, attackers can merely change the .ace extension to .rar extension to make it look normal.

Read the full news here.
[-] The following 5 users say Thank You to hanso for this post:
  • darktwilight, Deep900, harlan4096, silversurfer, wwd
Reply
#3
Thanks for this share guys, this is very important in terms of security and reliabiity.
[-] The following 4 users say Thank You to Deep900 for this post:
  • darktwilight, harlan4096, silversurfer, wwd
Reply
#4
WinRAR 5.70 Beta 2

Changelog: WinRAR archiver, a powerful tool to process RAR and ZIP files

Download: WinRAR archiver, a powerful tool to process RAR and ZIP files
[-] The following 2 users say Thank You to silversurfer for this post:
  • darktwilight, harlan4096
Reply
#5
Hi guys, 

I ask the WinRAR developer about this and this is his reply about the workaround. Which is either to (1) upgrade to WinRAR 5.70 beta 1 and 2 or (2) just delete the file "UNACEV2.DLL " manually from it's location. See quoted text below. 


Quote:Hello,

UNACEV2.DLL library which we used in WinRAR 5.61 and earlier to unpack
ACE files was vulnerable to directory traversal attack with a specially
crafted ACE archives. We already published WinRAR 5.70 beta 1 and 2
without this library and these 5.70 betas are not vulnerable.

Those users who do not want to upgrade to 5.70 just now, can delete
UNACEV2.DLL file to prevent this attack. Depending on WinRAR version,
UNACEV2.DLL can be resided either in WinRAR program folder or in Formats
subfolder of WinRAR program folder. Just delete this file manually
and it will prevent such attack.

Meanwhile we are working on WinRAR 5.70 release.

[Image: tWOmkM8.png]

The downloads links for WinRAR 5.70 beta 1 and 2 are posted above by silversurfer

As mentioned above if you do not want to upgrade to ver5.70 now, users can just delete the file below manually

Quote:UNACEV2.DLL file 

in the Program Files folder (or in Formats subfolder of WinRAR program folder)

[Image: PG8ddin.png]
[-] The following 5 users say Thank You to jasonX for this post:
  • darktwilight, dhruv2193, dinosaur07, harlan4096, silversurfer
Reply
#6
WinRAR 5.70 is out see below (from silversurfer),

Post#3
https://www.geeks.fyi/showthread.php?tid=88&highlight=WinRAR

The "UNACEV2.DLL file" as well as "ACE support" has been removed completely (as informed by WinRAR developer)
[-] The following 3 users say Thank You to jasonX for this post:
  • darktwilight, harlan4096, silversurfer
Reply
#7
A true-informative review of WinRAR 5.70 will be posted soon in the reviews section. Watch out for it soon!
[-] The following 2 users say Thank You to jasonX for this post:
  • harlan4096, silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
1.0.98 release (2024/05/19)
1.0.98 release (20...harlan4096 — 06:32
Chrome extensions may slow down browsing...
Extensions are one...harlan4096 — 06:31
How to turn off App Promotions in Windo...
disable app promotio...marcojanson42 — 09:42
Microsoft Edge 125.0.2535.51
Version 125.0.2535...harlan4096 — 06:59
NoVirusThanks OSArmor 1.9.9
OSArmor v1.9.9 rel...harlan4096 — 06:00

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (37)axuben
avatar (38)ihijudu
avatar (48)Mirzojap
avatar (34)idilysaju
avatar (38)odukoromu
avatar (44)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>