Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h4mr-p94x-gf79

Опубликовано: 10 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

EPSS

Процентиль: 100%
0.90964
Критический

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

CVSS3: 7.5
nvd
около 3 лет назад

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

CVSS3: 7.5
debian
около 3 лет назад

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal ...

suse-cvrf
около 3 лет назад

Security update for unrar

CVSS3: 4.3
fstec
около 3 лет назад

Уязвимость средства разархивирования файлов UnRAR, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю перезаписать произвольные файлы

EPSS

Процентиль: 100%
0.90964
Критический

7.5 High

CVSS3

Дефекты

CWE-22