Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2014-9983

Опубликовано: 04 июн. 2017
Источник: debian

Описание

Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rarfixed2:5.3.b2-1package
rarno-dsajessiepackage
rarno-dsawheezypackage
rarno-dsasqueezepackage

Примечания

  • Version 5.21 upstream changes behaviour: by default rar skips symbolic links

  • symbolic links with absolute paths in link target when extracting.

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.

CVSS3: 5.5
nvd
больше 8 лет назад

Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.

CVSS3: 5.5
github
больше 3 лет назад

Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.