First published: Sun Sep 03 2017(Updated: )
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] are unpacked into the upper directory.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
UnRAR | =0.0.1 | |
Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14120 is considered to be a medium severity vulnerability.
To fix CVE-2017-14120, upgrade unrar to the latest version available that is not susceptible to the vulnerability.
The main risk of CVE-2017-14120 is that it allows an attacker to exploit directory traversal to write files to unintended locations.
CVE-2017-14120 affects unrar version 0.0.1 and Debian Linux version 9.0.
Yes, if exploited, CVE-2017-14120 can potentially lead to overwriting or manipulation of files outside the target directory.