HIGH 7.5 Maven

Junrar vulnerable to infinite loop via extracting carefully crafted RAR archive

GHSA-m6cj-93v6-cvr5 · CVE-2022-23596

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

A carefully crafted RAR archive can trigger an infinite loop while extracting said archive. The impact depends solely on how the application uses the library, and whether files can be provided by malignant users.

Patches

The problem is partially patched in 7.4.1

Workarounds

None

References

https://github.com/junrar/junrar/issues/73

https://github.com/junrar/junrar/issues/81

Ready to move

Start Securing

Free, no credit card | First findings in minutes