Loading
Integer signedness error in the SET_VALUE function in rarvm.cpp in unrar 3.70 beta 3, as used in products including WinRAR and RAR for OS X, allows user-assisted remote attackers to cause a denial of service (crash) via a crafted RAR archive that causes a negative signed number to be cast to a large unsigned number.
Use Rarlab vendor hub and Unrar product page to widen CVE-2007-3726 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-30333, CVE-2017-12942 and CVE-2017-12941 for nearby disclosures in the same product family.