A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. An integer overflow can be caused in DataSize+CurChannel. The result is a negative value of the "DestPos" variable, which allows the attacker to write out of bounds when setting Mem[DestPos].
CVSS Details
- CVSS 3.0 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade clamav | Aug 22, 2024 | Jun 22, 2017 |
| Amazon_linux | — | Upgrade clamav | Mar 25, 2018 | Jun 22, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jun 22, 2017 |
| Debian | — | Upgrade libclamunrarUpgrade unrar-nonfree | Jun 28, 2017 | Jun 22, 2017 |
| Gentoo Linux | — | Upgrade media-tv/kodi.Upgrade app-antivirus/clamav.Upgrade app-arch/unrar.Upgrade app-arch/rar. | Oct 30, 2017 | Jun 22, 2017 |
| Oracle Solaris | — | Upgrade archiver/unrar to version 5.5.5-0.175.3.22.0.3.0 on Solaris 11.3 | Jul 19, 2017 | Jun 22, 2017 |
| Suse | — | Upgrade unrarUpgrade clamav-docs-htmlUpgrade libclammspack0Upgrade libclamav12Upgrade libunrar5_6_1Upgrade clamavUpgrade libclamav9Upgrade clamav-develUpgrade libunrar5_0_14Upgrade clamav-milterUpgrade libunrar-develUpgrade libclamav7Upgrade libfreshclam2Upgrade libfreshclam4Upgrade libfreshclam3 | Apr 26, 2018 | Jun 21, 2017 |
| Ubuntu | — | Upgrade unrar-nonfreeUpgrade libclamunrar | Nov 19, 2024 | Jun 22, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub