WinRAR Removes ACE Support to fix 19-Year-Old Vulnerability

Discussion of news of interest or importance.
Locked
User avatar
smed79
Liste AR/FR Author
Liste AR/FR Author
Posts: 15839
Joined: Sun Jan 17, 2010 4:00 am
Location: EasyList Forum

WinRAR Removes ACE Support to fix 19-Year-Old Vulnerability

Post by smed79 »

WinRAR Removes ACE Support to fix 19-Year-Old Vulnerability
WinRAR Version 5.70 wrote:Nadav Grossman from Check Point Software Technologies informed us
about a security vulnerability in UNACEV2.DLL library.
Aforementioned vulnerability makes possible to create files
in arbitrary folders inside or outside of destination folder
when unpacking ACE archives.

WinRAR used this third party library to unpack ACE archives.
UNACEV2.DLL had not been updated since 2005 and we do not have access
to its source code. So we decided to drop ACE archive format support
to protect security of WinRAR users.
Check Point Research blog post detailing how it works
https://research.checkpoint.com/extract ... om-winrar/

Video demo
https://www.youtube.com/watch?v=R2qcBWJzHMo

Update WinRAR
https://www.rarlab.com/download.htm
•► Read RULES / Use forum Search
••► Don't post clickable links
•••►Upload screenshots at imgbb.com
Locked