CVE-2005-4620 describes a buffer overflow vulnerability in WinRAR versions 3.50 and earlier, allowing local users to execute arbitrary code through a crafted, long command-line argument. This vulnerability has a CVSS score of 4.6, indicating low severity due to its local attack vector and the requirement for user interaction, resulting in potential partial confidentiality, integrity, and availability impact. While not actively exploited in the wild and not listed on the KEV catalog, exploit code for similar WinRAR buffer overflows (EDB-1403, EDB-1404) exists, though there is minimal community discussion or media coverage surrounding this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.90CPE matchmatch criteria | cpe:2.3:a:rarlab:winrar:2.90:*:*:*:*:*:*:* | ||
3.0.0CPE matchmatch criteria | cpe:2.3:a:rarlab:winrar:3.0.0:*:*:*:*:*:*:* | ||
3.10CPE matchmatch criteria | cpe:2.3:a:rarlab:winrar:3.10:*:*:*:*:*:*:* | ||
3.10_beta3CPE matchmatch criteria | cpe:2.3:a:rarlab:winrar:3.10_beta3:*:*:*:*:*:*:* | ||
3.10_beta5CPE matchmatch criteria | cpe:2.3:a:rarlab:winrar:3.10_beta5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.