First published: Mon May 09 2022(Updated: )
Last updated 12 March 2025
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
UnRAR | ||
UnRAR | <6.12 | |
Linux Kernel | ||
OpenGroup Unix | ||
All of | ||
UnRAR | <6.12 | |
Any of | ||
Linux Kernel | ||
OpenGroup Unix | ||
Debian Linux | =10.0 | |
debian/rar | 2:6.23-1~deb11u1 2:6.23-1~deb12u1 2:7.11-1 | |
debian/unrar-nonfree | 1:6.0.3-1+deb11u3 1:6.2.6-1+deb12u1 1:7.1.6-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30333 is a directory traversal vulnerability in RARLAB UnRAR before version 6.12 on Linux and UNIX systems.
CVE-2022-30333 allows for directory traversal during an extract operation, potentially allowing an attacker to write to files outside the intended directory.
CVE-2022-30333 has a severity level of high with a CVSS score of 7.5.
No, WinRAR and Android RAR are unaffected by CVE-2022-30333.
To mitigate CVE-2022-30333, update RARLAB UnRAR to version 6.12 or newer.