Description
github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause Denial of Service via an Out Of Memory Crash.
Problem types
CWE-789: Memory Allocation with Excessive Size Value
Product status
2.0.1
2.2.0
Credits
Juho Forsén
References
github.com/...ommit/52fb4e825c936636f251f7e7deded39ab11df9a9