CVE-2017-14502

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
17/09/2017
Last modified:
20/04/2025

Description

read_header in archive_read_support_format_rar.c in libarchive 3.3.2 suffers from an off-by-one error for UTF-16 names in RAR archives, leading to an out-of-bounds read in archive_read_format_rar_read_header.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:libarchive:libarchive:3.3.2:*:*:*:*:*:*:*