security advisorycriticaldebian
The RAR archiver allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3534-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany August 17, 2023 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : rar Version : 2:6.20-0.1~deb10u1 CVE ID : CVE-2022-30333 Debian Bug : 1012228 The RAR archiver allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. For Debian 10 buster, this problem has been fixed in version 2:6.20-0.1~deb10u1. We recommend that you upgrade your rar packages. For the detailed security status of rar please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/rar Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-4940-1 deals with a vulnerability found in ZIP, fixing potential unauthorized file access when unpacking archives.. Debian LTS, RAR Archiver, Security Update, Directory Traversal. . Severity: Critical. LinuxSecurity.com Team
Aug 17, 2023
•Critical
Debian LTS