CVE-2022-30333
RARLAB UnRAR Directory Traversal Vulnerability
CVSS
7.5
Alto
EPSS
99.1%
p100
KEV
SÍ
9 ago 2022
Exploit Today
80
0-100
Publicado: 9 may 2022 · Última mod.: 4 ago 2026 · CWE-22 · CWE-59
Producto
RARLAB / UnRAR
Vulnerabilidad
RARLAB UnRAR Directory Traversal Vulnerability
Añadido a KEV
9 ago 2022
Remediar antes de
30 ago 2022
Uso conocido en ransomware
Sí
Descripción resumida
RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.
Acción requerida
Apply updates per vendor instructions.
Notas
Vulnerability updated with version 6.12. Accessing link will download update information: https://www.rarlab.com/rar/rarlinux-x32-612.tar.gz; https://nvd.nist.gov/vuln/detail/CVE-2022-30333
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
- packetstormsecurity.comhttp://packetstormsecurity.com/files/167989/Zimbra-UnRAR-Path-Traversal.html
- blog.sonarsource.comhttps://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2023/08/msg00022.html
- security.gentoo.orghttps://security.gentoo.org/glsa/202309-04
- www.rarlab.comhttps://www.rarlab.com/rar/rarlinux-x32-612.tar.gz
- www.rarlab.comhttps://www.rarlab.com/rar_add.htm
- packetstormsecurity.comhttp://packetstormsecurity.com/files/167989/Zimbra-UnRAR-Path-Traversal.html
- blog.sonarsource.comhttps://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2023/08/msg00022.html
- security.gentoo.orghttps://security.gentoo.org/glsa/202309-04
- www.rarlab.comhttps://www.rarlab.com/rar/rarlinux-x32-612.tar.gz
- www.rarlab.comhttps://www.rarlab.com/rar_add.htm
- www.cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-30333