Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7v9q-j964-43qc

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

EPSS

Процентиль: 100%
0.93462
Критический

7.8 High

CVSS3

Дефекты

CWE-22
CWE-36

Связанные уязвимости

CVSS3: 7.8
nvd
около 7 лет назад

In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

CVSS3: 9.6
fstec
почти 7 лет назад

Уязвимость библиотеки unacev2.dll архиватора файлов WinRAR, позволяющая нарушителю разместить вредоносные файлы в произвольное место на диске

EPSS

Процентиль: 100%
0.93462
Критический

7.8 High

CVSS3

Дефекты

CWE-22
CWE-36