A vulnerability in unrar allows overwriting files during archive extraction

A vulnerability has been identified in the unrar utility (CVE-2022-30333), which allows files to be overwritten outside the current directory when extracting a specially crafted archive, depending on user permissions. The issue has been resolved in RAR 6.12 and unrar 6.1.7. The vulnerability manifests in versions for Linux, FreeBSD, and macOS, but does not affect builds for Android and Windows.

The problem is caused by the lack of proper validation of the "\/.." sequence in file paths specified in the archive, allowing extraction to bypass the base directory. For example, by placing "..\/ .ssh\/authorized_keys" in the archive, an attacker could attempt to overwrite the user's file "~\/ .ssh\/authorized_keys" during extraction.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster