CVE-2022-30333
09.05.2022, 08:15
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
| Vendor | Product | Version |
|---|---|---|
| rarlab | unrar | 𝑥 < 6.12 |
| debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions
Debian Releases
Debian Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| rar |
| ||||||||||
| unrar-nonfree |
|
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libclamunrar |
| ||||||||||||||||||
| rar |
| ||||||||||||||||||
| unrar-nonfree |
|
References