Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Mageia 8: MGASA-2022-0206 Moderate: Unrar Directory Traversal Threat

mageia
Calendar Grey May 25, 2022
Dist Mageia Esm H88
New release of unrar 6.12 addresses vulnerabilities related to directory traversal and improper file access permissions on Mageia environments.
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_ke...

Summary

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. (CVE-2022-30333)

References

- https://bugs.mageia.org/show_bug.cgi?id=30453

- https://www.suse.com/security/cve/CVE-2022-30333.html

- https://www.cve.org/CVERecord?id=CVE-2022-30333

Resolution

SRPMS

- 8/nonfree/unrar-6.00-3.1.mga8.nonfree

Publication date: 25 May 2022
URL: https://advisories.mageia.org/MGASA-2022-0206.html
Type: security
CVE: CVE-2022-30333

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here