CVE-2022-30333: RARLAB UnRAR Directory Traversal Vulnerability
Last updated 12 March 2025
Other sources
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorizedkeys file. NOTE: WinRAR and Android RAR are unaffected.
— Launchpad
RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/rarto a version that resolves this vulnerability.Fixed in 2:6.23-1~deb11u1Fixed in 2:6.23-1~deb12u1Fixed in 2:7.11-1 - Upgrade
Upgrade
debian/unrar-nonfreeto a version that resolves this vulnerability.Fixed in 1:6.0.3-1+deb11u3Fixed in 1:6.2.6-1+deb12u1Fixed in 1:7.1.6-1 - Upgrade
Upgrade
RARLAB UnRARto a version that resolves this vulnerability.Fixed in 6.12
Event History
Frequently Asked Questions
What is CVE-2022-30333?
CVE-2022-30333 is a directory traversal vulnerability in RARLAB UnRAR before version 6.12 on Linux and UNIX systems.
How does CVE-2022-30333 affect RARLAB UnRAR?
CVE-2022-30333 allows for directory traversal during an extract operation, potentially allowing an attacker to write to files outside the intended directory.
What is the severity level of CVE-2022-30333?
CVE-2022-30333 has a severity level of high with a CVSS score of 7.5.
Is RARLAB UnRAR on Windows and Android affected by CVE-2022-30333?
No, WinRAR and Android RAR are unaffected by CVE-2022-30333.
How can I mitigate the vulnerability?
To mitigate CVE-2022-30333, update RARLAB UnRAR to version 6.12 or newer.