WinRAR (Stable) 7.23 重要
複数のセキュリティ脆弱性を修正しました。RAR5 recovery volume処理の heap overflow と、抽出時の symbolic link による path traversal 攻撃の可能性を排除します。7zxa.dll ライブラリも最新版に更新されました。
1. Heap overflow vulnerability is fixed in RAR5 recovery volume data reconstruction code. It affects WinRAR, RAR and UnRAR. UnRAR.dll library doesn't include recovery volume processing, so it is not affected. We are thankful to Arjun Basnet from Securin Labs for letting us know about this security issue. 2. Symbolic link pointing outside of destination folder could be created even without -ola switch, when extracting a specially crafted RAR archive by WinRAR, RAR, UnRAR or UnRAR.…
「WinRAR 7.23」が公開 ~ヒープオーバーフローなど2件の脆弱性に対処/7zファイルの展開モジュールは「7-Zip 26.02」相当に(7/10更新)日本語版も7.23に更新を確認。