CVE ID | Publié | Description | Score | Gravité |
---|---|---|---|---|
UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains. | 7.5 |
Haute |
||
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected. | 7.5 |
Haute |
||
UnRAR 5.6.1.7 through 5.7.4 and 6.0.3 has an out-of-bounds write during a memcpy in QuickOpen::ReadRaw when called from QuickOpen::ReadNext. | 7.8 |
Haute |