CVE-2022-30333
09.05.2022, 08:15
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
Vendor | Product | Version |
---|---|---|
rarlab | unrar | 𝑥 < 6.12 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|
rar |
| ||||||||||
unrar-nonfree |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
libclamunrar |
| ||||||||||||||||||
rar |
| ||||||||||||||||||
unrar-nonfree |
|
References