

Rewterz Threat Advisory – CVE-2019-8956 – Linux Kernel “sctp_sendmsg()” Use-After-Free Vulnerability
February 21, 2019
Rewterz Threat Advisory – CVE-2019-1684 – Cisco IP Phone 8800/ Cisco IP Phone 7800 Vulnerability
February 21, 2019
Rewterz Threat Advisory – CVE-2019-8956 – Linux Kernel “sctp_sendmsg()” Use-After-Free Vulnerability
February 21, 2019
Rewterz Threat Advisory – CVE-2019-1684 – Cisco IP Phone 8800/ Cisco IP Phone 7800 Vulnerability
February 21, 2019Severity
Medium
Analysis Summary
The flaw resides in the way an old third-party library, called UNACEV2.DLL, used by the software handled the extraction of files compressed in ACE data compression archive file format. However, since WinRAR detects the format by the content of the file and not by the extension, attackers can merely change the .ace extension to .rar extension to make it look normal.
“Absolute Path Traversal” bug in the library that could be leveraged to execute arbitrary code on a targeted system attempting to uncompress a maliciously-crafted file archive using the vulnerable versions of the software.
The path traversal flaw allows attackers to extract compressed files to a folder of their choice rather than the folder chosen by the user, leaving an opportunity to drop malicious code into Windows Startup folder where it would automatically run on the next reboot.
Impact
System access.
Loss of sensitive information.
Affected Products
WinRAR (all versions)
Remediation
Install the latest version of WinRAR.
WINRar version 5.70 beta 1.