Path traversal in UnRar - CVE-2022-30333
Published: May 10, 2022 / Updated: August 9, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences when extracting files from archive. A remote attacker can create a specially crafted archive and overwrite arbitrary files on the system with privileges of the current user.
The vulnerability affects Linux and UNIX systems.
Affected software
Gentoo Linux
Ubuntu
clamav (Ubuntu package)
libclamunrar9 (Ubuntu package)
libclamunrar11 (Ubuntu package)
libunrar5 (Ubuntu package)
unrar (Ubuntu package)
app-arch/unrar
app-arch/rar
rar (Ubuntu package)
How to mitigate CVE-2022-30333
clamav (Ubuntu package) - addressed in versions 0.103.11+dfsg-0ubuntu0.20.04.1, 0.103.11+dfsg-0ubuntu0.22.04.1, 0.103.11+dfsg-0ubuntu0.23.04.1, 1.0.4+dfsg-0ubuntu0.23.10.1
libclamunrar9 (Ubuntu package) - addressed in versions 0.103.11-0ubuntu0.20.04.1, 0.103.11-0ubuntu0.22.04.1, 0.103.11-0ubuntu0.23.04.1
libclamunrar11 (Ubuntu package) - update to 1.0.4-0ubuntu0.23.10.1
libunrar5 (Ubuntu package) - addressed in versions 1:5.6.6-2ubuntu0.1, 1:6.1.5-1ubuntu0.1
unrar (Ubuntu package) - addressed in versions 1:5.6.6-2ubuntu0.1, 1:6.1.5-1ubuntu0.1
app-arch/unrar - update to 6.2.10
app-arch/rar - update to 6.23
rar (Ubuntu package) - addressed in versions 2:6.23-1~20.04.1, 2:6.23-1~22.04.1
Links to Public Exploits and PoC-codes
- Exploit #8229 - Zimbra UnRAR Path Traversal (August 9, 2022)
- Exploit #8214 - UnRAR Path Traversal in Zimbra (CVE-2022-30333) (August 4, 2022)
- Exploit #8215 - UnRAR Path Traversal (CVE-2022-30333) (August 4, 2022)
- Exploit #8181 - Zimbra-CVE-2022-30333 (Zimbra unrar vulnerability. Now there are already POC available, it is safe to release our POC.) (July 26, 2022)
- Exploit #8165 - CVE-2022-30333 () (July 24, 2022)
- Exploit #8149 - unrar-cve-2022-30333-poc () (July 18, 2022)
- Exploit #8110 - CVE-2022-30333-PoC () (July 5, 2022)