HIGH 7.5 Maven
Junrar vulnerable to infinite loop via extracting carefully crafted RAR archive
GHSA-m6cj-93v6-cvr5 · CVE-2022-23596
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
A carefully crafted RAR archive can trigger an infinite loop while extracting said archive. The impact depends solely on how the application uses the library, and whether files can be provided by malignant users.
Patches
The problem is partially patched in 7.4.1
Workarounds
None
References
References
- WEB https://github.com/junrar/junrar/security/advisories/GHSA-m6cj-93v6-cvr5
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2022-23596
- WEB https://github.com/junrar/junrar/issues/73
- WEB https://github.com/junrar/junrar/commit/7b16b3d90b91445fd6af0adfed22c07413d4fab7
- PACKAGE https://github.com/junrar/junrar
Ready to move
Start Securing
Free, no credit card | First findings in minutes