CVE-2022-30333
KEV
🔴 Łataj teraz
Przechodzenie do katalogów w UnRAR umożliwia zapis plików podczas rozpakowywania.
CVSS
7.5
EPSS
99.1%
Exploit
weaponized
Vendor
debian
Opis źródłowy (NVD)
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
exploit path-traversal
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 99.1% |
| Opublikowano (NVD) | 2022-05-09 08:15:06 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-04 05:16:28 UTC |
Referencje
- http://packetstormsecurity.com/files/167989/Zimbra-UnRAR-Path-Traversal.html (cve@mitre.org) [Exploit, Third Party Advisory, VDB Entry]
- https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/ (cve@mitre.org) [Exploit, Third Party Advisory]
- https://lists.debian.org/debian-lts-announce/2023/08/msg00022.html (cve@mitre.org) [Mailing List, Third Party Advisory]
- https://security.gentoo.org/glsa/202309-04 (cve@mitre.org) [Third Party Advisory]
- https://www.rarlab.com/rar/rarlinux-x32-612.tar.gz (cve@mitre.org) [Patch]
- https://www.rarlab.com/rar_add.htm (cve@mitre.org) [Product]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-30333 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]