Is TC subject to this RAR vulnerability?
Moderators: Hacker, petermad, Stefan2, white
Is TC subject to this RAR vulnerability?
Hello,
a RAR vulnerability has just been published and fixed a few days ago.
Even opening (not even unpacking) an infected file can trigger this vulnerability.
Is TC11 subject to this vulnerability?
https://www.zerodayinitiative.com/advisories/ZDI-23-1152
a RAR vulnerability has just been published and fixed a few days ago.
Even opening (not even unpacking) an infected file can trigger this vulnerability.
Is TC11 subject to this vulnerability?
https://www.zerodayinitiative.com/advisories/ZDI-23-1152
Regards, Brahman
Win10 & 11 Pro x64
Win10 & 11 Pro x64
- ghisler(Author)
- Site Admin
- Posts: 50400
- Joined: 2003-02-04, 09:46 UTC
- Location: Switzerland
- Contact:
Re: Is TC subject to this RAR vulnerability?
No one knows whether unrar.dll is affected too, or just winrar itself. But since I'm currently preparing the relase of TC 11.01 anyway, I will include the new unrar dlls with it.
If you can't update or don't want to update, you can use the new dlls from rarlab:
https://www.rarlab.com/rar_add.htm (click on UnRAR.dll)
If you can't update or don't want to update, you can use the new dlls from rarlab:
https://www.rarlab.com/rar_add.htm (click on UnRAR.dll)
Author of Total Commander
https://www.ghisler.com
https://www.ghisler.com
Re: Is TC subject to this RAR vulnerability?
Thank you very much for your advice.
I have already replaced the rar and unrar exes on all my other utilities.
Now that you gave me the link, I can also replace the dlls. There are quite a few on my computer.
I have already replaced the rar and unrar exes on all my other utilities.
Now that you gave me the link, I can also replace the dlls. There are quite a few on my computer.
Regards, Brahman
Win10 & 11 Pro x64
Win10 & 11 Pro x64
- ghisler(Author)
- Site Admin
- Posts: 50400
- Joined: 2003-02-04, 09:46 UTC
- Location: Switzerland
- Contact:
Re: Is TC subject to this RAR vulnerability?
I have also put the 2 DLLs plus the one I compiled myself for Windows 9x/ME in a separate ZIP installer:
https://www.ghisler.com/unrardll.htm
Just download the ZIP and double click on it in Total Commander to install the new DLLs.
https://www.ghisler.com/unrardll.htm
Just download the ZIP and double click on it in Total Commander to install the new DLLs.
Author of Total Commander
https://www.ghisler.com
https://www.ghisler.com
Re: Is TC subject to this RAR vulnerability?
Linkrarlabs website wrote:the original unrar.dll and unrar64.dll libraries provided on our site are not vulnerable
"War is evil, in so far as it makes more bad people than it takes away."
Immanuel Kant in "Perpetual Peace"
Immanuel Kant in "Perpetual Peace"
Re: Is TC subject to this RAR vulnerability?
FYI:
history.txt wrote:21.08.23 Release Total Commander 11.01 release candidate 1
.
.
20.08.23 Fixed: Updated unrar.dll, unrar64.dll and unrar9x.dll (compiled by us for Windows 9x/ME) to latest version 6.23.0 to fix security hole (32/64)
License #524 (1994)
Danish Total Commander Translator
TC 11.51 32+64bit on Win XP 32bit & Win 7, 8.1 & 10 (22H2) 64bit, 'Everything' 1.5.0.1391a
TC 3.60b4 on Android 6, 13, 14
TC Extended Menus | TC Languagebar | TC Dark Help | PHSM-Calendar
Danish Total Commander Translator
TC 11.51 32+64bit on Win XP 32bit & Win 7, 8.1 & 10 (22H2) 64bit, 'Everything' 1.5.0.1391a
TC 3.60b4 on Android 6, 13, 14
TC Extended Menus | TC Languagebar | TC Dark Help | PHSM-Calendar
- ghisler(Author)
- Site Admin
- Posts: 50400
- Joined: 2003-02-04, 09:46 UTC
- Location: Switzerland
- Contact:
Re: Is TC subject to this RAR vulnerability?
Thanks for the info, so the DLLs are not affected. The DLL sources include the files recvol3.cpp und recvol5.cpp, so I assumed that the DLL would also be affected by the security issue in the recovery volume functions.
This gives me a bit more time to release TC 11.01 with less haste.
This gives me a bit more time to release TC 11.01 with less haste.
Author of Total Commander
https://www.ghisler.com
https://www.ghisler.com