CVE-2022-23596
Junrar vulnerable to infinite loop via extracting carefully crafted RAR archive
7.5
HIGH
CVSS 3.1
EPSS 1.6%
描述
### Impact A carefully crafted RAR archive can trigger an infinite loop while extracting said archive. The impact depends solely on how the application uses the library, and whether files can be provided by malignant users. ### Patches The problem is partially patched in 7.4.1 ### Workarounds None ### References https://github.com/junrar/junrar/issues/73 https://github.com/junrar/junrar/issues/81
如何修補 CVE-2022-23596
要修補 CVE-2022-23596,請將受影響套件升級到下列已修補版本。
- —升級至 7.4.1 或更新版本
CVE-2022-23596 正在被利用嗎?
低 — EPSS 為 1.6%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 7.4.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |