Bugzilla – Bug 1214058
VUL-0: CVE-2022-48579: unrar: extraction of files outside of the destination folder via symlink chains.
Last modified: 2023-08-11 15:31:58 UTC
CVE-2022-48579 UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-48579 https://www.cve.org/CVERecord?id=CVE-2022-48579 https://github.com/pmachapman/unrar/commit/2ecab6bb5ac4f3b88f270218445496662020205f#diff-ca3086f578522062d7e390ed2cd7e10f646378a8b8cbf287a6e4db5966df68ee
The patch does not apply cleanly in SLE-12, I am working to fix it.
Couldn't manage to trigger the bug on maintained codestreams, we're not affected. Closing.