First published: Mon May 09 2022(Updated: )
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
RARLAB UnRAR | <6.12 | |
Linux Linux kernel | ||
Opengroup Unix | ||
ubuntu/libclamunrar | <0.103.11-0ubuntu0.20.04.1 | 0.103.11-0ubuntu0.20.04.1 |
ubuntu/libclamunrar | <0.103.11-0ubuntu0.22.04.1 | 0.103.11-0ubuntu0.22.04.1 |
ubuntu/libclamunrar | <0.103.11-0ubuntu0.23.04.1 | 0.103.11-0ubuntu0.23.04.1 |
ubuntu/libclamunrar | <0.103.7<0.105.1 | 0.103.7 0.105.1 |
ubuntu/rar | <2:6.23-1 | 2:6.23-1 |
ubuntu/rar | <2:6.23-1 | 2:6.23-1 |
ubuntu/rar | <2:6.23-1 | 2:6.23-1 |
ubuntu/unrar-nonfree | <1:6.1.7-1 | 1:6.1.7-1 |
debian/rar | <=2:5.5.0-1 | 2:6.23-1~deb10u1 2:6.23-1~deb11u1 2:6.23-1~deb12u1 2:7.00-1 |
debian/unrar-nonfree | 1:5.6.6-1+deb10u1 1:5.6.6-1+deb10u4 1:6.0.3-1+deb11u3 1:6.2.6-1+deb12u1 1:7.0.8-1 | |
All of | ||
RARLAB UnRAR | <6.12 | |
Any of | ||
Linux Linux kernel | ||
Opengroup Unix | ||
Debian Debian Linux | =10.0 | |
RARLAB UnRAR |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30333 is a directory traversal vulnerability in RARLAB UnRAR before version 6.12 on Linux and UNIX systems.
CVE-2022-30333 allows for directory traversal during an extract operation, potentially allowing an attacker to write to files outside the intended directory.
CVE-2022-30333 has a severity level of high with a CVSS score of 7.5.
No, WinRAR and Android RAR are unaffected by CVE-2022-30333.
To mitigate CVE-2022-30333, update RARLAB UnRAR to version 6.12 or newer.