CVE-2004-1254 describes a critical vulnerability in WinRAR 3.40 and earlier versions, allowing remote code execution through specially crafted ZIP files containing excessively long filenames. This flaw likely stems from an integer overflow leading to a buffer overflow. With a CVSS score of 10.0, this vulnerability is highly severe, requiring no authentication and having a low attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, an ExploitDB entry exists, and the vulnerability garners significant community discussion, indicating potential interest despite no known active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.0CPE matchmatch criteria | cpe:2.3:a:rarlab:winrar:3.0.0:*:*:*:*:*:*:* | ||
3.10CPE matchmatch criteria | cpe:2.3:a:rarlab:winrar:3.10:*:*:*:*:*:*:* | ||
3.10_beta3CPE matchmatch criteria | cpe:2.3:a:rarlab:winrar:3.10_beta3:*:*:*:*:*:*:* | ||
3.10_beta5CPE matchmatch criteria | cpe:2.3:a:rarlab:winrar:3.10_beta5:*:*:*:*:*:*:* | ||
3.11CPE matchmatch criteria | cpe:2.3:a:rarlab:winrar:3.11:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.