CVE-2022-48579: High severity unrar vulnerability
Published Aug 7, 2023
·Updated
Last updated 12 March 2025
Other sources
UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.
— MITRE
Affected Software
2 affected componentsFixes available
RARLAB UnRAR<6.2.3
debian/unrar-nonfree
1:6.0.3-1+deb11u31:6.2.6-1+deb12u11:7.1.6-1
Remediation
Event History
Aug 7, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 12, 2025
Data Sourced
via Launchpad·09:40 PM
Description
Mar 16, 2025
Data Sourced
via Ubuntu·09:40 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·09:41 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2022-48579?
CVE-2022-48579 is a vulnerability that allows the extraction of files outside of the destination folder in UnRAR before version 6.2.3 through symlink chains.
2
How severe is CVE-2022-48579?
CVE-2022-48579 has a severity rating of 7.5, which is classified as high.
3
What software is affected by CVE-2022-48579?
The RARLAB UnRAR software versions up to and excluding 6.2.3 are affected by CVE-2022-48579.
4
How can the files outside of the destination folder be extracted?
The files outside of the destination folder can be extracted through symlink chains.
5
Is there a fix for CVE-2022-48579?
Yes, updating to UnRAR version 6.2.3 or later will fix the vulnerability.