Executive brief
RARLAB UnRAR on Linux and UNIX systems contains a directory traversal vulnerability during the extraction (unpack) process. An attacker can exploit this to write arbitrary files to the filesystem, potentially leading to remote code execution as demonstrated by the creation of authorized_keys files.
Affected products
- RARLAB UnRAR before 6.12
Timeline
- 2022-08-09: disclosed
- 2022-08-09: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-08-09: advisory: NVD publication date
- 2022-08-09: exploited: Reported as exploited in the wild in CISA KEV catalog.