Lack of data validation - Path Traversal In unrar-nonfree
Description
UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 11 | =1:3.5.2-0.1 || =1:3.5.2-0.2 || =1:3.5.4-0.1 || =1:3.5.4-1 || =1:3.5.4-1.1 || =1:3.7.2-1 || =1:3.7.3-1 || =1:3.7.3-1.1 || =1:3.7.8-1 || =1:3.7.8-2 || =1:3.8.2-1 || =1:3.8.4-1 || =1:3.8.5-1 || =1:3.8.5-2 || =1:3.9.10-1 || =1:3.9.3-1 || =1:3.9.5-1 || =1:3.9.6-1 || =1:3.9.7-1 || =1:3.9.9-1 || =1:4.0.2-1 || =1:4.0.3-1 || =1:4.1.4-1 || =1:4.2.4-0.1 || =1:4.2.4-0.2 || =1:4.2.4-0.3 || =1:5.0.10-1 || =1:5.2.5-1 || =1:5.2.7-0.1 || =1:5.3.2-1 || =1:5.4.5-1 || =1:5.5.5-1 || =1:5.5.8-1 || =1:5.6.6-1 || =1:5.6.6-2 || =1:5.9.4-1 || =1:6.0.3-1 || =1:6.0.3-1+deb11u1 || =3.3.6-2 || =3.3.6-2.0.1 || =3.4.3-1 || >=0 <1:6.0.3-1+deb11u2 | 1:6.0.3-1+deb11u2 | |
debian 12 | =1:3.5.2-0.1 || =1:3.5.2-0.2 || =1:3.5.4-0.1 || =1:3.5.4-1 || =1:3.5.4-1.1 || =1:3.7.2-1 || =1:3.7.3-1 || =1:3.7.3-1.1 || =1:3.7.8-1 || =1:3.7.8-2 || =1:3.8.2-1 || =1:3.8.4-1 || =1:3.8.5-1 || =1:3.8.5-2 || =1:3.9.10-1 || =1:3.9.3-1 || =1:3.9.5-1 || =1:3.9.6-1 || =1:3.9.7-1 || =1:3.9.9-1 || =1:4.0.2-1 || =1:4.0.3-1 || =1:4.1.4-1 || =1:4.2.4-0.1 || =1:4.2.4-0.2 || =1:4.2.4-0.3 || =1:5.0.10-1 || =1:5.2.5-1 || =1:5.2.7-0.1 || =1:5.3.2-1 || =1:5.4.5-1 || =1:5.5.5-1 || =1:5.5.8-1 || =1:5.6.6-1 || =1:5.6.6-2 || =1:5.9.4-1 || =1:6.0.3-1 || =1:6.0.4-1 || =1:6.0.4-2 || =1:6.0.5-1 || =1:6.0.6-1 || =1:6.0.7-1 || =1:6.0.7-2 || =1:6.0.7-3 || =1:6.0.7-4 || =1:6.0.7-5 || =1:6.0.7-6 || =1:6.1.2-1 || =1:6.1.3-1 || =1:6.1.3-2 || =1:6.1.4-1 || =1:6.1.5-1 || =1:6.1.6-1 || =1:6.1.6-2 || =1:6.1.6-3 || =1:6.1.7-1 || =1:6.1.7-2 || =1:6.1.7-3 || =1:6.1.7-4 || =1:6.2.1-1 || =1:6.2.1-2 || =1:6.2.2-1 || =1:6.2.2-2 || =3.3.6-2 || =3.3.6-2.0.1 || =3.4.3-1 || >=0 <1:6.2.3-1 | 1:6.2.3-1 | |
debian 13 | =1:3.5.2-0.1 || =1:3.5.2-0.2 || =1:3.5.4-0.1 || =1:3.5.4-1 || =1:3.5.4-1.1 || =1:3.7.2-1 || =1:3.7.3-1 || =1:3.7.3-1.1 || =1:3.7.8-1 || =1:3.7.8-2 || =1:3.8.2-1 || =1:3.8.4-1 || =1:3.8.5-1 || =1:3.8.5-2 || =1:3.9.10-1 || =1:3.9.3-1 || =1:3.9.5-1 || =1:3.9.6-1 || =1:3.9.7-1 || =1:3.9.9-1 || =1:4.0.2-1 || =1:4.0.3-1 || =1:4.1.4-1 || =1:4.2.4-0.1 || =1:4.2.4-0.2 || =1:4.2.4-0.3 || =1:5.0.10-1 || =1:5.2.5-1 || =1:5.2.7-0.1 || =1:5.3.2-1 || =1:5.4.5-1 || =1:5.5.5-1 || =1:5.5.8-1 || =1:5.6.6-1 || =1:5.6.6-2 || =1:5.9.4-1 || =1:6.0.3-1 || =1:6.0.4-1 || =1:6.0.4-2 || =1:6.0.5-1 || =1:6.0.6-1 || =1:6.0.7-1 || =1:6.0.7-2 || =1:6.0.7-3 || =1:6.0.7-4 || =1:6.0.7-5 || =1:6.0.7-6 || =1:6.1.2-1 || =1:6.1.3-1 || =1:6.1.3-2 || =1:6.1.4-1 || =1:6.1.5-1 || =1:6.1.6-1 || =1:6.1.6-2 || =1:6.1.6-3 || =1:6.1.7-1 || =1:6.1.7-2 || =1:6.1.7-3 || =1:6.1.7-4 || =1:6.2.1-1 || =1:6.2.1-2 || =1:6.2.2-1 || =1:6.2.2-2 || =3.3.6-2 || =3.3.6-2.0.1 || =3.4.3-1 || >=0 <1:6.2.3-1 | 1:6.2.3-1 | |
debian 14 | =1:3.5.2-0.1 || =1:3.5.2-0.2 || =1:3.5.4-0.1 || =1:3.5.4-1 || =1:3.5.4-1.1 || =1:3.7.2-1 || =1:3.7.3-1 || =1:3.7.3-1.1 || =1:3.7.8-1 || =1:3.7.8-2 || =1:3.8.2-1 || =1:3.8.4-1 || =1:3.8.5-1 || =1:3.8.5-2 || =1:3.9.10-1 || =1:3.9.3-1 || =1:3.9.5-1 || =1:3.9.6-1 || =1:3.9.7-1 || =1:3.9.9-1 || =1:4.0.2-1 || =1:4.0.3-1 || =1:4.1.4-1 || =1:4.2.4-0.1 || =1:4.2.4-0.2 || =1:4.2.4-0.3 || =1:5.0.10-1 || =1:5.2.5-1 || =1:5.2.7-0.1 || =1:5.3.2-1 || =1:5.4.5-1 || =1:5.5.5-1 || =1:5.5.8-1 || =1:5.6.6-1 || =1:5.6.6-2 || =1:5.9.4-1 || =1:6.0.3-1 || =1:6.0.4-1 || =1:6.0.4-2 || =1:6.0.5-1 || =1:6.0.6-1 || =1:6.0.7-1 || =1:6.0.7-2 || =1:6.0.7-3 || =1:6.0.7-4 || =1:6.0.7-5 || =1:6.0.7-6 || =1:6.1.2-1 || =1:6.1.3-1 || =1:6.1.3-2 || =1:6.1.4-1 || =1:6.1.5-1 || =1:6.1.6-1 || =1:6.1.6-2 || =1:6.1.6-3 || =1:6.1.7-1 || =1:6.1.7-2 || =1:6.1.7-3 || =1:6.1.7-4 || =1:6.2.1-1 || =1:6.2.1-2 || =1:6.2.2-1 || =1:6.2.2-2 || =3.3.6-2 || =3.3.6-2.0.1 || =3.4.3-1 || >=0 <1:6.2.3-1 | 1:6.2.3-1 |
Does your application use this vulnerable software?
During the free trial, our tools assess your application, identify vulnerabilities, and provide recommendations for their remediation.