CVE-2022-30333
גבוהה 7.5 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- RARLAB UnRAR Directory Traversal Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N - EPSS — סבירות ניצול
- 99% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-22, CWE-59
מוצרים מושפעים
rarlab: unrar; linux: linux kernel; opengroup: unix; debian: debian linux
קישורים
- https://www.rarlab.com/rar/rarlinux-x32-612.tar.gz Patch
- https://www.rarlab.com/rar/rarlinux-x32-612.tar.gz Patch
- http://packetstormsecurity.com/files/167989/Zimbra-UnRAR-Path-Traversal.html ExploitThird Party AdvisoryVDB Entry
- https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/ ExploitThird Party Advisory
- http://packetstormsecurity.com/files/167989/Zimbra-UnRAR-Path-Traversal.html ExploitThird Party AdvisoryVDB Entry
- https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/ ExploitThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/08/msg00022.html Mailing ListThird Party Advisory
- https://security.gentoo.org/glsa/202309-04 Third Party Advisory
- https://www.rarlab.com/rar_add.htm Product
- https://lists.debian.org/debian-lts-announce/2023/08/msg00022.html Mailing ListThird Party Advisory