Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
A specific flaw within the processing of recovery volumes exists in RAR, an archive program for rar files. It allows remote attackers to execute arbitrary code on affected installations. User interaction is required to exploit this vulnerability. The target must visit a malicious page or open a . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3543-1
Multiple vulnerabilities have been found in RAR and UnRAR, the worst of which may allow attackers to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 201709-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: RAR, UnRAR: Multiple vulnerabilities Date: September 25, 2017 Bugs: #622342, #628182, #628184 ID: 201709-24 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Multiple vulnerabilities have been found in RAR and UnRAR, the worst of which may allow attackers to execute arbitrary code. Background ========= RAR and UnRAR provide command line interfaces for compressing and decompressing RAR files. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-arch/rar < 5.5.0_p20170811 > = 5.5.0_p20170811 2 app-arch/unrar < 5.5.7 > = 5.5.7 ------------------------------------------------------------------- 2 affected packages Description ========== Multiple vulnerabilities have been discovered in RAR and UnRAR. Please review the referenced CVE identifiers for details. Impact ===== A remote attacker, by enticing a user to open a specially crafted RAR, could possibly execute arbitrary code with the privileges of the process or cause a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All RAR users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-arch/rar-5.5.0_p20170811" All UnRARusers should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-arch/unrar-5.5.7" References ========= [ 1 ] CVE-2012-6706 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-6706 [ 2 ] CVE-2017-12940 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12940 [ 3 ] CVE-2017-12941 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12941 [ 4 ] CVE-2017-12942 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-12942 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/201709-24 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.