7.5.5
12 years ago
1 years ago
Known vulnerabilities in the com.github.junrar:junrar package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
com.github.junrar:junrar is a rar decompression library in plain java. Affected versions of this package are vulnerable to Denial of Service (DoS). A carefully crafted RAR archive can trigger an infinite loop while parsing the file. Note: The impact depends solely on how the application uses the library, and whether files can be provided by malignant users. How to fix Denial of Service (DoS)? Upgrade | [,7.4.1) |
com.github.junrar:junrar is a plain java unrar util. Affected versions of this package are vulnerable to Denial of Service (DoS) attacks due to an infinite loop when handling corrupt RAR files. How to fix Denial of Service (DoS)? Upgrade | [,1.0.1) |