CVE-2007-3726

Publication date 12 July 2007

Last updated 17 July 2025


Ubuntu priority

Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number.

Status

Package Ubuntu Release Status
unrar-nonfree 9.10 karmic
Fixed 3.7.3-1.1
9.04 jaunty
Fixed 3.7.3-1.1
8.10 intrepid
Fixed 3.7.3-1.1
8.04 LTS hardy
Fixed 3.7.3-1.1
7.10 gutsy
Fixed 3.7.3-1.1
7.04 feisty Ignored end of life, was needed
6.10 edgy Ignored end of life, was needed
6.06 LTS dapper Ignored end of life