Umbra Wiki cve cve/CVE-2022-30333
Back to wiki

CVE-2022-30333 — RARLAB UnRAR Directory Traversal Vulnerability

provenance: imported · CVE: CVE-2022-30333

CVE-2022-30333: RARLAB UnRAR Directory Traversal Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project RARLAB
Product UnRAR
Date added 2022-08-09
Due date 2022-08-30
Ransomware campaign use Known

Description

RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.

Required action (CISA)

Apply updates per vendor instructions.

Notes

Vulnerability updated with version 6.12. Accessing link will download update information: https://www.rarlab.com/rar/rarlinux-x32-612.tar.gz; https://nvd.nist.gov/vuln/detail/CVE-2022-30333

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-30333
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog