Huge security vulnerability found in Winrar

linuxares

The inadequate, autocratic beast!
OP
Global Moderator
Joined
Aug 5, 2007
Messages
13,370
Trophies
2
XP
18,288
Country
Sweden

ModernSithLord

Member
Newcomer
Joined
Nov 13, 2023
Messages
20
Trophies
0
Age
31
XP
77
Country
United States
This will not be the last time the we hear winrar & vulnerability in the same sentence. Glad i use 7zip & stopped using winrar a long time ago. I am not shocked either an apt is the one's utilizing this vuln.
 
  • Like
Reactions: Jayro

console

Elvira fans ❤ :-) I'm rocking Windows 7 for 11 yrs
Member
Joined
Mar 1, 2013
Messages
391
Trophies
1
Location
In heart of Windows XP, 7. I ❤ 👠! 🥰
Website
www.startpage.com
XP
3,385
Country
United States
I just updated my WinRAR to 6.23 that fixed vulnerability.

I had 7-zip and use for many years since Windows XP to now. ;)

I heard about Peazip is very nice and have support for all Windows, Linux and Mac OS. :yay:

Recommend update to WinRAR 6.23 and above should be fine.
 
  • Like
Reactions: linuxares

linuxares

The inadequate, autocratic beast!
OP
Global Moderator
Joined
Aug 5, 2007
Messages
13,370
Trophies
2
XP
18,288
Country
Sweden
I just updated my WinRAR to 6.23 that fixed vulnerability.

I had 7-zip and use for many years since Windows XP to now. ;)

I heard about Peazip is very nice and have support for all Windows, Linux and Mac OS. :yay:

Recommend update to WinRAR 6.23 and above should be fine.
Yepp! It was already fixed when the blog was posted. So it was just a "heads up, update please!" post :)
If you wanna continue to use Winrar I highly recommend anyone that use it to update to be secure!
 
  • Like
Reactions: console

Dust2dust

Well-Known Member
Member
Joined
Jun 17, 2010
Messages
2,430
Trophies
2
XP
4,425
Country
Canada
I thought it would be some kind of backdoor for password-protected files. This brought back old memories of installing Winrar when I was using Windows, and then registering with a keygen or something similar, just for the heck. :D
 
  • Like
Reactions: console

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,077
Country
United States
I thought it would be some kind of backdoor for password-protected files. This brought back old memories of installing Winrar when I was using Windows, and then registering with a keygen or something similar, just for the heck. :D
Funnily enough, you can use a keygen to license it under anything, including things like 7-Zip. The rar command line utility is the same piece of software across all operating systems and archive tools, and a Windows keygen will give you a valid key file. Just plop it somewhere rar can see it, and it'll accept it. Here it is on Linux:
Code:
> $ cat /etc/rarreg.key                                                                                             
RAR registration data
Joom
Unlimited Company License
UID=XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%

> $ rar                                                                                                             

RAR 5.50   Copyright (c) 1993-2017 Alexander Roshal   11 Aug 2017
Registered to Joom
 

Dust2dust

Well-Known Member
Member
Joined
Jun 17, 2010
Messages
2,430
Trophies
2
XP
4,425
Country
Canada
Funnily enough, you can use a keygen to license it under anything, including things like 7-Zip. The rar command line utility is the same piece of software across all operating systems and archive tools, and a Windows keygen will give you a valid key file. Just plop it somewhere rar can see it, and it'll accept it. Here it is on Linux:
Code:
> $ cat /etc/rarreg.key                                                                                            
RAR registration data
Joom
Unlimited Company License
UID=XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%

> $ rar                                                                                                            

RAR 5.50   Copyright (c) 1993-2017 Alexander Roshal   11 Aug 2017
Registered to Joom
I know it doesn't make a difference if it's registered or not, but I just tried with an old (like 10 years old) rarreg.key I had lying around, and it worked as you described. BTW, I wonder why they use such an old version by default on Linux. I upgraded while I was at it.
Code:
> $ rar

RAR 6.24   Copyright (c) 1993-2023 Alexander Roshal   3 Oct 2023
Registered to SeVeN

Usage:     rar <command> -<switch 1> -<switch N> <archive> <files...>
               <@listfiles...> <path_to_extract/>
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,077
Country
United States
BTW, I wonder why they use such an old version by default on Linux.

Licensing, if I had to guess. I imagine maintainers aren't a fan of maintaining it. For example, it's only available through the AUR on Arch. There is a FOSS version of the unrar utility, but it's kinda lacking, as it's essentially just a plugin/wrapper for libarchive.
https://gitlab.com/bgermann/unrar-free
 
  • Like
Reactions: Dust2dust

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • K3Nv2 @ K3Nv2:
    Thanks for signing up at LinusTechTips
  • QuarterCut @ QuarterCut:
    holey shmoley!
  • BigOnYa @ BigOnYa:
    Your credit card has been charged. Thank you.
  • K3Nv2 @ K3Nv2:
    Your screwdriverPlus will arrive in three weeks
    +1
  • QuarterCut @ QuarterCut:
    K64_Waddle_Dee_Artwork_1.jpg

    my reaction to such information
    +2
  • BigOnYa @ BigOnYa:
    Press 1 for English. Press 2 for Pig Latin. Or press 3 to speak to a representative.
  • BakerMan @ BakerMan:
    guys, i need help, i got into an argument about what genre radioactive is, and i forgot who made it
  • Sicklyboy @ Sicklyboy:
    @BakerMan, Imagine Dragons
  • Sicklyboy @ Sicklyboy:
    Dragon deez nuts across yo face GOTEEM
  • Sicklyboy @ Sicklyboy:
    lmao now I realize that was probably the joke in the first place
    +1
  • BakerMan @ BakerMan:
    IMAGINE DRAGON DEEZ NUTS ACROSS YO- FUCK HE BEAT ME TO IT
  • BigOnYa @ BigOnYa:
    You have selected 4 - Death by Snu Snu, please stand by...
    +1
  • BakerMan @ BakerMan:
    lucky bastard
    +1
  • Sicklyboy @ Sicklyboy:
    hahahaha I'm half way through a bag off my Volcano and my tolerance is way down because I haven't been smoking much lately, so I was a little slow to catch that that was what your angle was 🤣🤣
    +1
  • Sicklyboy @ Sicklyboy:
    Also I was just excited to know a music reference for once (I am the LAST person in the world that you want on your trivia team)
    +2
  • K3Nv2 @ K3Nv2:
    Bummer webos 7.4 isnt working with dejavuln-autoroot
  • Sicklyboy @ Sicklyboy:
    PS4 right? I think that's what mine's on. Or 5.6, maybe.
  • K3Nv2 @ K3Nv2:
    [!] Installation failed (devmode_enabled not recognized)
  • K3Nv2 @ K3Nv2:
    0.5 seemed to work whatever lol i wont bitch
  • Alysh_Graham @ Alysh_Graham:
    Hehehe
    Alysh_Graham @ Alysh_Graham: Hehehe