RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
2022-05-09T08:15:06.937
2025-03-13T15:35:00.390
Analyzed
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rarlab | unrar | < 6.12 | Yes |
Operating System | linux | linux_kernel | - | No |
Operating System | opengroup | unix | - | No |
Operating System | debian | debian_linux | 10.0 | Yes |