Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-9983


Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.


Published

2017-06-04T23:29:00.187

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rarlab rar 4.00 Yes
Application rarlab rar 4.01 Yes
Application rarlab rar 4.10 Yes
Application rarlab rar 4.11 Yes
Application rarlab rar 4.20 Yes
Application rarlab rar 5.00 Yes
Application rarlab rar 5.01 Yes
Application rarlab rar 5.10 Yes
Application rarlab rar 5.11 Yes
Application rarlab rar 5.20 Yes
Application rarlab rar 5.21 Yes
Application rarlab rar 5.30 Yes
Application rarlab rar 5.31 Yes
Application rarlab rar 5.40 Yes
Application rarlab rar 5.50 Yes
Application rarlab rar 5.50 Yes
Application rarlab rar 5.50 Yes
Application rarlab rar 5.50 Yes

References