Vulnerability in unrar dll - updated dlls

Bug reports will be moved here when the described bug has been fixed

Moderators: Hacker, petermad, Stefan2, white

Axel
Junior Member
Junior Member
Posts: 44
Joined: 2004-03-03, 12:29 UTC

Re: Vulnerability in unrar dll - updated dlls

Post by *Axel »

Thank you for the info.

And where is the original source of the used "lzma.dll"s (32-/64-bit) used for "TCMDLZMA.DLL and "TCLZMA64.DLL"?
On Igor Pavlovs page I can only download "lzma.exe", but no dll...

I now expect you compile them yourself too?
Fla$her
Power Member
Power Member
Posts: 3196
Joined: 2020-01-18, 04:03 UTC

Re: Vulnerability in unrar dll - updated dlls

Post by *Fla$her »

ghisler(Author) wrote: 2025-08-13, 06:39 UTC This happens because you didn't set a path to rar.exe or winrar.exe in Configuration - Options - Packer.
It's a strange explanation. I shouldn't have to do this on a clean TC, especially considering that WinRAR might not be installed at all. As for my build, I've already mentioned that I have the path to Rar.exe specified.
I will completely remove the loading of unrar.dll from other folders than the program folder, it could load an old unrar dll.
Good.
1. Does the loading of the unrar9x.dll work when you rename or delete the unrar.dll in the path?
2. When you rename or remove unrar9x.dll too, does TC use tc7z.dll now?
1. Yes.
2. Yes.

I was looking for this file not just for nothing, but specifically for these tests.
Overquoting is evil! 👎
User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 51386
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Re: Vulnerability in unrar dll - updated dlls

Post by *ghisler(Author) »

And where is the original source of the used "lzma.dll"s (32-/64-bit) used for "TCMDLZMA.DLL and "TCLZMA64.DLL"?
On Igor Pavlovs page I can only download "lzma.exe", but no dll...
It's also on https://www.7-zip.org/download.html under the name "LZMA SDK: (C, C++, C#, Java)".
Unfortunately it's only version 25.00, so I updated the few changed files from "7-Zip Source code" 25.01 from the same page.
Author of Total Commander
https://www.ghisler.com
User avatar
Dalai
Power Member
Power Member
Posts: 10187
Joined: 2005-01-28, 22:17 UTC
Location: Meiningen (Südthüringen)

Re: Vulnerability in unrar dll - updated dlls

Post by *Dalai »

2ghisler(Author)
The up-to-date one is here: https://www.7-zip.org/sdk.html
#101164 Personal licence
Ryzen 5 2600, 16 GiB RAM, ASUS Prime X370-A, Win7 x64

Plugins: Services2, Startups, CertificateInfo, SignatureInfo, LineBreakInfo - Download-Mirror
User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 51386
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Re: Vulnerability in unrar dll - updated dlls

Post by *ghisler(Author) »

Thanks, that's identical to what I put together myself.
Author of Total Commander
https://www.ghisler.com
Axel
Junior Member
Junior Member
Posts: 44
Joined: 2004-03-03, 12:29 UTC

Re: Vulnerability in unrar dll - updated dlls

Post by *Axel »

Thanks @ghisler and @Dalai, but in the mentioned downloads I can't see any DLLs, just EXEs?
User avatar
Dalai
Power Member
Power Member
Posts: 10187
Joined: 2005-01-28, 22:17 UTC
Location: Meiningen (Südthüringen)

Re: Vulnerability in unrar dll - updated dlls

Post by *Dalai »

2Axel
Well, you asked for the original source for the DLL, and it's exactly that. There doesn't seem to be a pre-compiled lzma.dll as far as I can see.
#101164 Personal licence
Ryzen 5 2600, 16 GiB RAM, ASUS Prime X370-A, Win7 x64

Plugins: Services2, Startups, CertificateInfo, SignatureInfo, LineBreakInfo - Download-Mirror
User avatar
ghisler(Author)
Site Admin
Site Admin
Posts: 51386
Joined: 2003-02-04, 09:46 UTC
Location: Switzerland
Contact:

Re: Vulnerability in unrar dll - updated dlls

Post by *ghisler(Author) »

Moderator message from: ghisler(Author) » 2025-10-12, 07:40 UTC

Moved to fixed bugs
Author of Total Commander
https://www.ghisler.com
Post Reply