CVE-2022-30333
Description
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
Summary dbcve.org
UnRAR before version 6.12 on Linux and UNIX contains a directory traversal vulnerability that allows attackers to write files to arbitrary locations outside the intended extraction directory during unpack operations, potentially enabling remote code execution by overwriting sensitive files like SSH authorized_keys.
Mitigation
Upgrade UnRAR to version 6.12 or later to remediate this vulnerability. On POSIX systems, verify that automated extraction pipelines or user-facing unzip utilities that may bundle vulnerable UnRAR versions are also updated.