Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Is Keka affected as well by this RAR issue allowing arbitrary memory writes? #43

Closed
rpkoller opened this issue Jun 21, 2017 · 5 comments
Assignees
Milestone

Comments

@rpkoller
Copy link

https://bugs.chromium.org/p/project-zero/issues/detail?id=1286&can=1&q=unrar&desc=6

@aonez aonez self-assigned this Jun 21, 2017
@aonez aonez added this to the 1.0.9 milestone Jun 21, 2017
@aonez
Copy link
Owner

aonez commented Jun 21, 2017

It is, since it's using unrar 5.4. Updating to 5.50 beta 4 with fixed code right ahead.

Thanks for the tip!

@aonez aonez closed this as completed Jun 21, 2017
@aonez
Copy link
Owner

aonez commented Jun 21, 2017

Already released: https://github.com/aonez/Keka/releases/tag/v1.0.9
The MAS update will be propagating very soon :)

@rpkoller
Copy link
Author

MAS is also available now. Thanks a lot for the quick fix!

@aronkihui
Copy link

This version, v1.0.9 (stable now -in theory- XD), can't unRAR an encrypted password rar file. It drops me an error coded 255. :(

@aonez
Copy link
Owner

aonez commented Jul 2, 2017

@aronkihui this was a bug reintroduced in 1.0.9 as you said (#48), just released 1.0.10 with this fixed. Sorry for that.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants