
Cloud Vulnerability DB
A community-led vulnerabilities database
RARLAB WinRAR before version 7.00, on Linux and UNIX platforms, contains an ANSI escape sequence injection vulnerability that allows attackers to spoof screen output or cause denial of service. The vulnerability, discovered by security researcher Siddharth Dushantha and disclosed on February 28, 2024, affects the console versions of RAR and UnRAR in versions 6.24 and earlier. It's important to note that the GUI version of WinRAR and the UnRAR library were not impacted by this vulnerability (Medium Blog, SecurityOnline).
The vulnerability leverages ANSI escape sequences, which are special codes used to control text formatting, colors, and cursor positioning in terminals. The issue stems from WinRAR's failure to filter ANSI escape sequences in the archive comment section, allowing attackers to inject malicious ANSI codes. The vulnerability has been assigned a CVSS v3.1 Base Score of 7.1 (HIGH) with the vector string CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H. The weakness is classified as CWE-150: Improper Neutralization of Escape, Meta, or Control Sequences (NVD).
The vulnerability can be exploited in two primary ways: attackers can spoof file listings by injecting malicious ANSI codes into archive comments, potentially tricking users into opening harmful files disguised as harmless ones, and on Linux and Unix systems, specific ANSI sequences can trigger a local denial-of-service condition, rendering the terminal unusable. The impact is more severe on Linux and Unix systems due to the potential for denial-of-service attacks (SecurityOnline).
A proof-of-concept exploit has been demonstrated where attackers can hide malicious files (e.g., virus.exe) within an archive and replace their names in the file listing with seemingly harmless ones (e.g., notvirus.pdf). The vulnerability can be triggered by injecting ANSI escape sequences into archive comments, which are then processed when listing the contents of the archive using unrar l command (Medium Blog).
RARLAB has addressed this vulnerability in WinRAR version 7.00. The fix includes filtering out character 27 from screen output, which is used to declare ANSI escape control sequences in terminal applications. Users are strongly advised to update their software to version 7.00 or later to protect against potential attacks (RARLAB).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."