CVE-2022-30333

unknown KEV
Published 2022-08-09 ยท Modified 2022-08-09
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
2.5

Description

RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.

CISA KEV

Vendor
RARLAB
Product
UnRAR
Due date
2022-08-30

Predictions

Exploit likelihood
99%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27
{Vendor advisory: cisa-kev โ€” Vulnerability updated with version 6.12. Accessing link will download update information: https://www.rarlab.com/rar/rarlinux-x32-612.tar.gz; https://nvd.nist.gov/vuln/detail/CVE-2022-30333}

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Metasploit modules

UnRAR Path Traversal (CVE-2022-30333)
Source code queued for fetch โ€” refresh in a moment.
UnRAR Path Traversal in Zimbra (CVE-2022-30333)
Source code queued for fetch โ€” refresh in a moment.

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 2:6.20~b1-0.1
sid Fixed 2:6.20~b1-0.1
forky Fixed 2:6.20~b1-0.1
bullseye Fixed 2:6.20-0.1~deb11u1
bookworm Fixed 2:6.20~b1-0.1

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.