Skip to content

Potential Vulnerability in Cloned Code#207

Closed
tabudz wants to merge 1 commit intokanryu:masterfrom
tabudz:cve-2017-20006
Closed

Potential Vulnerability in Cloned Code#207
tabudz wants to merge 1 commit intokanryu:masterfrom
tabudz:cve-2017-20006

Conversation

@tabudz
Copy link

@tabudz tabudz commented Dec 12, 2025

Summary

Our tool detected a potential vulnerability in unrar/unrar/recvol5.cpp which was cloned from aawc/unrar but did not receive the security patch applied. The original issue was reported and fixed under https://nvd.nist.gov/vuln/detail/cve-2017-20006.

Proposed Fix

Apply the same patch as the one in aawc/unrar to eliminate the vulnerability.

Reference

https://nvd.nist.gov/vuln/detail/cve-2017-20006
aawc/unrar@0ff832d

@kanryu
Copy link
Owner

kanryu commented Dec 12, 2025

Thank you for reporting the security vulnerability. :)
Although this project is now closed, we will make an exception for this issue.
However, we will use unrar's official meticulous implementation instead of the automatic fix you created.

@kanryu kanryu closed this Dec 12, 2025
@kanryu
Copy link
Owner

kanryu commented Dec 12, 2025

I made it! :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants