Warning: Critical WinRAR Flaw Affects All Versions Released In Last 19 Years
#5
Hi guys, 

I ask the WinRAR developer about this and this is his reply about the workaround. Which is either to (1) upgrade to WinRAR 5.70 beta 1 and 2 or (2) just delete the file "UNACEV2.DLL " manually from it's location. See quoted text below. 


Quote:Hello,

UNACEV2.DLL library which we used in WinRAR 5.61 and earlier to unpack
ACE files was vulnerable to directory traversal attack with a specially
crafted ACE archives. We already published WinRAR 5.70 beta 1 and 2
without this library and these 5.70 betas are not vulnerable.

Those users who do not want to upgrade to 5.70 just now, can delete
UNACEV2.DLL file to prevent this attack. Depending on WinRAR version,
UNACEV2.DLL can be resided either in WinRAR program folder or in Formats
subfolder of WinRAR program folder. Just delete this file manually
and it will prevent such attack.

Meanwhile we are working on WinRAR 5.70 release.

[Image: tWOmkM8.png]

The downloads links for WinRAR 5.70 beta 1 and 2 are posted above by silversurfer

As mentioned above if you do not want to upgrade to ver5.70 now, users can just delete the file below manually

Quote:UNACEV2.DLL file 

in the Program Files folder (or in Formats subfolder of WinRAR program folder)

[Image: PG8ddin.png]
[-] The following 5 users say Thank You to jasonX for this post:
  • darktwilight, dhruv2193, dinosaur07, harlan4096, silversurfer
Reply


Messages In This Thread
RE: Warning: Critical WinRAR Flaw Affects All Versions Released In Last 19 Years - by jasonX - 25 February 19, 14:52

Forum Jump:


Users browsing this thread: 2 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AdGuard for iOS v4.5.16
AdGuard for iOS v4...harlan4096 — 07:24
QOwnNotes
26.2.9  Fixed a v...Kool — 05:38
AdGuard for Android 4.12.3
AdGuard for Androi...harlan4096 — 17:18
Replit Pro – One Month Free
Replit Pro     C...hanso — 17:02
Free 4 months Adobe Express subscription
Free 4 months Ado...hanso — 12:27

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (46)dimaWeami
avatar (44)Baihu

[-]
Online Staff
hanso's profile hanso

>