com.github.junrar:junrar@0.7 vulnerabilities

  • latest version

    7.5.5

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    1 years ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the com.github.junrar:junrar package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Denial of Service (DoS)

    com.github.junrar:junrar is a rar decompression library in plain java.

    Affected versions of this package are vulnerable to Denial of Service (DoS). A carefully crafted RAR archive can trigger an infinite loop while parsing the file.

    Note: The impact depends solely on how the application uses the library, and whether files can be provided by malignant users.

    How to fix Denial of Service (DoS)?

    Upgrade com.github.junrar:junrar to version 7.4.1 or higher.

    [,7.4.1)
    • M
    Denial of Service (DoS)

    com.github.junrar:junrar is a plain java unrar util.

    Affected versions of this package are vulnerable to Denial of Service (DoS) attacks due to an infinite loop when handling corrupt RAR files.

    How to fix Denial of Service (DoS)?

    Upgrade com.github.junrar:junrar to version 1.0.1 or higher.

    [,1.0.1)