CVE-2017-14120: Path Traversal
Published Sep 3, 2017
·Updated
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] are unpacked into the upper directory.
Affected Software
2 affected components
RARLAB UnRAR=0.0.1
Debian Debian Linux=9.0
Event History
Sep 3, 2017
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14120?
CVE-2017-14120 is considered to be a medium severity vulnerability.
2
How do I fix CVE-2017-14120?
To fix CVE-2017-14120, upgrade unrar to the latest version available that is not susceptible to the vulnerability.
3
What are the risks associated with CVE-2017-14120?
The main risk of CVE-2017-14120 is that it allows an attacker to exploit directory traversal to write files to unintended locations.
4
Which software is affected by CVE-2017-14120?
CVE-2017-14120 affects unrar version 0.0.1 and Debian Linux version 9.0.
5
Can CVE-2017-14120 lead to data loss?
Yes, if exploited, CVE-2017-14120 can potentially lead to overwriting or manipulation of files outside the target directory.