------------------------------------------------------------------------- Debian LTS Advisory DLA-3534-1 [email protected] https://www.debian.org/lts/security/ Markus Koschany August 17, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : rar Version : 2:6.20-0.1~deb10u1 CVE ID : CVE-2022-30333 Debian Bug : 1012228 The RAR archiver allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. For Debian 10 buster, this problem has been fixed in version 2:6.20-0.1~deb10u1. We recommend that you upgrade your rar packages. For the detailed security status of rar please refer to its security tracker page at: https://security-tracker.debian.org/tracker/rar Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS