Unrated severityNVD Advisory· Published Jul 25, 2006· Updated Apr 16, 2026
CVE-2006-3845
CVE-2006-3845
Description
Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.
Affected products
18cpe:2.3:a:rarlab:winrar:3.0.0:*:*:*:*:*:*:*+ 17 more
- cpe:2.3:a:rarlab:winrar:3.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.10:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.10_beta3:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.10_beta5:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.11:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.20:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.30:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.40:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.41:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.42:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.50:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.51:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.60_beta1:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.60_beta2:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.60_beta3:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.60_beta4:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.60_beta5:*:*:*:*:*:*:*
- cpe:2.3:a:rarlab:winrar:3.60_beta6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- secunia.com/advisories/21080nvdPatchVendor Advisory
- hustlelabs.com/advisories/04072006_rarlabs.pdfnvdExploitVendor Advisory
- www.rarlabs.com/rarnew.htmnvd
- www.securityfocus.com/bid/19043nvd
- www.vupen.com/english/advisories/2006/2867nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/27815nvd
News mentions
0No linked articles in our index yet.