It was discovered that there was a directory traversal vulnerability in unrar-free, a unarchiver for .rar files, where pathnames of the form "../filename" were unpacked into the parent directory. . Hash: SHA256 Package : unrar-free Version : 1:0.0.1+cvs20071127-2+deb7u1 CVE ID : CVE-2017-14120 Debian Bug : #874059 It was discovered that there was a directory traversal vulnerability in unrar-free, a unarchiver for .rar files, where pathnames of the form "../filename" were unpacked into the parent directory. For Debian 7 "Wheezy", this issue has been fixed in unrar-free version 1:0.0.1+cvs20071127-2+deb7u1. We recommend that you upgrade your unrar-free packages. Regards, - -- ,'`. : :' : Chris Lamb `. `'`
Get the latest Linux and open source security news straight to your inbox.