TROYANOSYVIRUS
Voltar para CVEs

CVE-2022-30333

HIGHCISA KEV
7.5

Descricao

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

Detalhes CVE

Pontuacao CVSS v3.17.5
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado5/9/2022
Ultima modificacao11/3/2025
Fontekev
Avistamentos honeypot0

CISA KEV

FornecedorRARLAB
ProdutoUnRAR
Nome da vulnerabilidadeRARLAB UnRAR Directory Traversal Vulnerability
Data inclusao KEV2022-08-09
Prazo de remediacao2022-08-30
Uso em ransomwareKnown

Produtos afetados

debian:debian_linuxlinux:linux_kernelopengroup:unixrarlab:unrar

Fraquezas (CWE)

CWE-22CWE-22CWE-59

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.