10-08-2022, 13:08 door nicolaasjan

Dit is een kwetsbaarheid in UnRar voor Linux/UNIX. CVE-2022-30333. https://nvd.nist.gov/vuln/detail/CVE-2022-30333 Current Description RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected. Patch source code: https://www.rarlab.com/rar/rarlinux-x32-612.tar.gz https://tracker.debian.org/news/1352219/accepted-unrar-nonfree-1566-1deb10u1-source-into-oldstable-proposed-updates-oldstable-new-oldstable-proposed-updates/

