Alerts This Week
Warning Icon 1 938
Alerts This Week
Warning Icon 1 938

Ubuntu 7349-1: RAR Security Advisory Updates

ubuntu
Calendar Grey March 12, 2025
Dist Ubuntu Esm H88
Multiple security issues in RAR addressed in Ubuntu Security Notice USN-7349-1 for versions 20.04 and 22.04 LTS.
Several security issues were fixed in RAR.

Summary

Several security issues were fixed in RAR.

Software Description:

- rar: Archiver for .rar files

Details:

It was discovered that RAR incorrectly handled certain paths. If a user or

automated system were tricked into extracting a specially crafted RAR

archive, a remote attacker could possibly use this issue to write arbitrary

files outside of the targeted directory. (CVE-2022-30333)

It was discovered that RAR incorrectly handled certain recovery volumes. If

a user or automated system were tricked into extracting a specially crafted

RAR archive, a remote attacker could possibly use this issue to execute

arbitrary code. (CVE-2023-40477)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
   rar                             2:6.23-1~22.04.1

Ubuntu 20.04 LTS
   rar                             2:6.23-1~20.04.1

This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.

References

https://ubuntu.com/security/notices/USN-7349-1

CVE-2022-30333, CVE-2023-40477

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7349-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here