NA

CVE-2022-48579

Published: 07/08/2023 Updated: 17/08/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

UnRAR prior to 6.2.3 allows extraction of files outside of the destination folder via symlink chains.

Vulnerable Product Search on Vulmon Subscribe to Product

rarlab unrar

Vendor Advisories

Debian Bug report logs - #1050080 unrar: Fix CVE-2022-48579 for Debian 11 Package: unrar; Maintainer for unrar is UnRar maintainer team <team+unrar-nonfree@trackerdebianorg>; Source for unrar is src:unrar-nonfree (PTS, buildd, popcon) Reported by: YOKOTA Hiroshi <yokotahgml@gmailcom> Date: Sat, 19 Aug 2023 13:09: ...