Warning: Critical WinRAR Flaw Affects All Versions Released In Last 19 Years
#5
Hi guys, 

I ask the WinRAR developer about this and this is his reply about the workaround. Which is either to (1) upgrade to WinRAR 5.70 beta 1 and 2 or (2) just delete the file "UNACEV2.DLL " manually from it's location. See quoted text below. 


Quote:Hello,

UNACEV2.DLL library which we used in WinRAR 5.61 and earlier to unpack
ACE files was vulnerable to directory traversal attack with a specially
crafted ACE archives. We already published WinRAR 5.70 beta 1 and 2
without this library and these 5.70 betas are not vulnerable.

Those users who do not want to upgrade to 5.70 just now, can delete
UNACEV2.DLL file to prevent this attack. Depending on WinRAR version,
UNACEV2.DLL can be resided either in WinRAR program folder or in Formats
subfolder of WinRAR program folder. Just delete this file manually
and it will prevent such attack.

Meanwhile we are working on WinRAR 5.70 release.

[Image: tWOmkM8.png]

The downloads links for WinRAR 5.70 beta 1 and 2 are posted above by silversurfer

As mentioned above if you do not want to upgrade to ver5.70 now, users can just delete the file below manually

Quote:UNACEV2.DLL file 

in the Program Files folder (or in Formats subfolder of WinRAR program folder)

[Image: PG8ddin.png]
[-] The following 5 users say Thank You to jasonX for this post:
  • darktwilight, dhruv2193, dinosaur07, harlan4096, silversurfer
Reply


Messages In This Thread
RE: Warning: Critical WinRAR Flaw Affects All Versions Released In Last 19 Years - by jasonX - 25 February 19, 14:52

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Geekbench flags Intel Binary Optimizatio...
Geekbench Browser ...harlan4096 — 07:41
AMD adds GFX1171 and GFX1172 to its “RDN...
AMD RDNA 4m aka RD...harlan4096 — 07:39
Intel introduces Core Ultra Series 3 vPr...
Intel Core Ultra S...harlan4096 — 07:38
Intel launches Arc Pro B70 at $949 with ...
Intel launches Arc...harlan4096 — 07:36
Google Rolls Out Android Auto Update To ...
Google has begun r...harlan4096 — 07:34

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (46)qaqapeti

[-]
Online Staff
There are no staff members currently online.

>