Warning: Critical WinRAR Flaw Affects All Versions Released In Last 19 Years
#5
Hi guys, 

I ask the WinRAR developer about this and this is his reply about the workaround. Which is either to (1) upgrade to WinRAR 5.70 beta 1 and 2 or (2) just delete the file "UNACEV2.DLL " manually from it's location. See quoted text below. 


Quote:Hello,

UNACEV2.DLL library which we used in WinRAR 5.61 and earlier to unpack
ACE files was vulnerable to directory traversal attack with a specially
crafted ACE archives. We already published WinRAR 5.70 beta 1 and 2
without this library and these 5.70 betas are not vulnerable.

Those users who do not want to upgrade to 5.70 just now, can delete
UNACEV2.DLL file to prevent this attack. Depending on WinRAR version,
UNACEV2.DLL can be resided either in WinRAR program folder or in Formats
subfolder of WinRAR program folder. Just delete this file manually
and it will prevent such attack.

Meanwhile we are working on WinRAR 5.70 release.

[Image: tWOmkM8.png]

The downloads links for WinRAR 5.70 beta 1 and 2 are posted above by silversurfer

As mentioned above if you do not want to upgrade to ver5.70 now, users can just delete the file below manually

Quote:UNACEV2.DLL file 

in the Program Files folder (or in Formats subfolder of WinRAR program folder)

[Image: PG8ddin.png]
[-] The following 5 users say Thank You to jasonX for this post:
  • darktwilight, dhruv2193, dinosaur07, harlan4096, silversurfer
Reply


Messages In This Thread
RE: Warning: Critical WinRAR Flaw Affects All Versions Released In Last 19 Years - by jasonX - 25 February 19, 14:52

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
[Test & Review Request] Looking for fee...
Can you at least i...LFTyyy — 14:28
Surfshark VPN : Award-winning VPN servi...
Dausos: Surfshark'...jasonX — 14:08
K-Lite Codec Pack 19.6.6 / 19.6.7 Update
Changes in 19.6.6:...harlan4096 — 07:37
AdGuard for iOS 4.5.19
AdGuard for iOS 4....harlan4096 — 07:35
Adobe Acrobat Reader DC 26.001.21431
Adobe Acrobat Read...harlan4096 — 07:34

[-]
Birthdays
Today's Birthdays
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo
avatar (38)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>