WinRAR 3.62 fixes 7-Zip archive handling vulnerability
WinRAR 3.62 is a release clearly dedicated to improving modules that handle third-party compression formats, 7z and gzip to be more precise.
The fix for 7-Zip’s format is the most notable since it targets a stack overflow vulnerability.
The bug in gzip handling was, at most, an inconvenience: sometimes the date for an extracted file could be set incorrectly.
Apparently, these flaws affected only the Windows build of WinRAR, since the version numbers for the Linux, BSD and Mac OS X build are the same (3.60).
*** WHAT’S NEW IN WINRAR 3.62 ***
- Stack overflow vulnerability has been corrected in WinRAR module processing 7-Zip archives;
- WinRAR GZip module could set a wrong file date when unpacking GZip archives.
*** DOWNLOAD AND OTHER LINKS ***
Download WinRAR 3.62 for Windows (exe installer – 1MB, MD5 Hash: 15CE577F46BDA1DFA2C8B10A8D0A02E5)
Download RAR 3.60 for Linux
(.tar.gz package, 735KB)
Download RAR 3.60 for FreeBSD
(.tar.gz package, 700KB, md5 = 25B783A1D98E1311002244E40380D91B)
Download RAR 3.60 for MacOS X
(.tar.gz package, 357KB, md5 = 41E6B7F4A9ABC797B612DAD55D3DCC3D)
Browse FTP Directory (other languages, themes, older releases)
