Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9983

Опубликовано: 04 июн. 2017
Источник: debian
EPSS Низкий

Описание

Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rarfixed2:5.3.b2-1package
rarno-dsajessiepackage
rarno-dsawheezypackage
rarno-dsasqueezepackage

Примечания

  • Version 5.21 upstream changes behaviour: by default rar skips symbolic links

  • symbolic links with absolute paths in link target when extracting.

EPSS

Процентиль: 77%
0.01768
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 9 лет назад

Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.

CVSS3: 5.5
nvd
около 9 лет назад

Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.

CVSS3: 5.5
github
больше 4 лет назад

Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.

EPSS

Процентиль: 77%
0.01768
Низкий