Umbra Wiki cve cve/CVE-2022-30333
Back to wiki

CVE-2022-30333 — RARLAB UnRAR Directory Traversal Vulnerability

provenance: imported · CVE: CVE-2022-30333 · CWE: CWE-22 CWE-59

CVE-2022-30333: RARLAB UnRAR Directory Traversal Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project RARLAB
Product UnRAR
Date added 2022-08-09
Due date 2022-08-30
Ransomware campaign use Known

Description

RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.

Required action (CISA)

Apply updates per vendor instructions.

Notes

Vulnerability updated with version 6.12. Accessing link will download update information: https://www.rarlab.com/rar/rarlinux-x32-612.tar.gz; https://nvd.nist.gov/vuln/detail/CVE-2022-30333

Weakness behind it

CISA records this vulnerability as an instance of CWE-22, CWE-59. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2022-30333
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →