Sunday, November 04, 2007

WinRAR Format String

A WinRAR format string error exists when displaying an invalid file name in a UUE/XXE encoded file error message. This exploit allows the non-authenticated user, when decoding a maliciously malformed UUE/XXE file, to execute arbitrary code on the system because of a stack-based buffer overflow.