CVE-2012-6706
A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.0%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. An integer overflow can be caused in DataSize+CurChannel. The result is a negative value of the "DestPos" variable, which allows the attacker to write out of bounds when setting Mem[DestPos].
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 10.03% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- sophos/threat detection engine · rarlab/unrar
- Source
- cve@mitre.org
References
- http://securitytracker.com/id?1027725Third Party Advisory
- http://telussecuritylabs.com/threats/show/TSL20121207-01Third Party Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1286Exploit, Third Party Advisory
- https://community.sophos.com/kb/en-us/118424#sixVendor Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10205
- https://lock.cmpxchg8b.com/sophailv2.pdfThird Party Advisory
- https://nakedsecurity.sophos.com/2012/11/05/tavis-ormandy-sophos/Vendor Advisory
- https://security.gentoo.org/glsa/201708-05
- https://security.gentoo.org/glsa/201709-24
- https://security.gentoo.org/glsa/201804-16
- http://securitytracker.com/id?1027725Third Party Advisory
- http://telussecuritylabs.com/threats/show/TSL20121207-01Third Party Advisory
- https://bugs.chromium.org/p/project-zero/issues/detail?id=1286Exploit, Third Party Advisory
- https://community.sophos.com/kb/en-us/118424#sixVendor Advisory
- https://kc.mcafee.com/corporate/index?page=content&id=SB10205
- https://lock.cmpxchg8b.com/sophailv2.pdfThird Party Advisory
- https://nakedsecurity.sophos.com/2012/11/05/tavis-ormandy-sophos/Vendor Advisory
- https://security.gentoo.org/glsa/201708-05
- https://security.gentoo.org/glsa/201709-24
- https://security.gentoo.org/glsa/201804-16
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.