Path traversal in UnRar - CVE-2022-30333

 

Path traversal in UnRar - CVE-2022-30333

Published: May 10, 2022 / Updated: August 9, 2022


Vulnerability identifier: #VU62908
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-30333
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences when extracting files from archive. A remote attacker can create a specially crafted archive and overwrite arbitrary files on the system with privileges of the current user.

The vulnerability affects Linux and UNIX systems.


Affected software

UnRar
Gentoo Linux
Ubuntu
clamav (Ubuntu package)
libclamunrar9 (Ubuntu package)
libclamunrar11 (Ubuntu package)
libunrar5 (Ubuntu package)
unrar (Ubuntu package)
app-arch/unrar
app-arch/rar
rar (Ubuntu package)

How to mitigate CVE-2022-30333

Install update from vendor's website.

UnRar - update to 6.12
clamav (Ubuntu package) - addressed in versions 0.103.11+dfsg-0ubuntu0.20.04.1, 0.103.11+dfsg-0ubuntu0.22.04.1, 0.103.11+dfsg-0ubuntu0.23.04.1, 1.0.4+dfsg-0ubuntu0.23.10.1
libclamunrar9 (Ubuntu package) - addressed in versions 0.103.11-0ubuntu0.20.04.1, 0.103.11-0ubuntu0.22.04.1, 0.103.11-0ubuntu0.23.04.1
libclamunrar11 (Ubuntu package) - update to 1.0.4-0ubuntu0.23.10.1
libunrar5 (Ubuntu package) - addressed in versions 1:5.6.6-2ubuntu0.1, 1:6.1.5-1ubuntu0.1
unrar (Ubuntu package) - addressed in versions 1:5.6.6-2ubuntu0.1, 1:6.1.5-1ubuntu0.1
app-arch/unrar - update to 6.2.10
app-arch/rar - update to 6.23
rar (Ubuntu package) - addressed in versions 2:6.23-1~20.04.1, 2:6.23-1~22.04.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins