CVE detail
CVE-2022-30333
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 26.4 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
13 source links · newest first
Threat actors are actively exploiting multiple Common Vulnerabilities and Exposures (CVEs) against enterprise cloud-hosted collaboration software and email platform Zimbra Collaboration Suite (ZCS), according to an advisory update jointly issued by the US Cybersecurity and Infrastructure Security Agency (CISA) and the Multi-State Information Sharing and Analysis Center (MS-ISAC). The latest update lists CVEs currently being […]
newswww.csoonline.comOct 20, 2022, 11:23 AMThe Zimbra Collaboration Suite is impacted by a critical remote code execution vulnerability that remains unpatched, despite being exploited in attacks.
newswww.securityweek.comOct 10, 2022, 1:12 PM- Unpatched Zimbra RCE bug exploited by attackers (CVE-2022-41352)Help Net Security
A still unpatched vulnerability (CVE-2022-41352) in Zimbra Collaboration is being exploited by attackers to achieve remote code execution on vulnerable servers. About the vulnerability Zimbra Collaboration (formerly Zimbra Collaboration Suite) is cloud-hosted collaboration software suite that also includes an email server component and a web client component. CVE-2022-41352 exists due to Zimbra’s Amavis antivirus engine using the cpio method to scan inbound emails. “CVE-2022-41352 is effectively identical to CVE-2022-30333 but leverages a different file format … More →
newswww.helpnetsecurity.comOct 10, 2022, 12:09 PM The US Cybersecurity and Infrastructure Security Agency (CISA) revealed on Tuesday that a recently patched vulnerability affecting the UnRAR archive extraction tool is being exploited in the wild.
newswww.securityweek.comAug 10, 2022, 10:49 AMUS Critical Infrastructure Security Agency (CISA) adds vulnerabilities in the UnRAR utility to its Known Exploited Vulnerabilities Catalog. The Cybersecurity & Infrastructure Security Agency (CISA) has added a recently disclosed security flaw, tracked as CVE-2022-30333 (CVSS score: 7.5), in the UnRAR utility to its Known Exploited Vulnerabilities Catalog. The CVE-2022-30333 flaw is a path traversal […]
newssecurityaffairs.comAug 10, 2022, 10:39 AMResearchers discovered a new flaw in RARlab’s UnRAR utility, tracked CVE-2022-30333, that can allow to remotely hack Zimbra Webmail servers. SonarSource researchers have discovered a new vulnerability in RARlab’s UnRAR utility, tracked as CVE-2022-30333, that can be exploited by remote attackers to execute arbitrary code on a system that relies on the binary, like Zimbra […]
newssecurityaffairs.comJun 29, 2022, 2:48 PMNo excerpt available.
Mitigationwww.cisa.govMay 9, 2022, 8:15 AM- https://www.rarlab.com/rar_add.htmwww.rarlab.com
No excerpt available.
Patchwww.rarlab.comMay 9, 2022, 8:15 AM - https://www.rarlab.com/rar/rarlinux-x32-612.tar.gzwww.rarlab.com
No excerpt available.
Patchwww.rarlab.comMay 9, 2022, 8:15 AM - https://security.gentoo.org/glsa/202309-04security.gentoo.org
No excerpt available.
Vendor Advisorysecurity.gentoo.orgMay 9, 2022, 8:15 AM No excerpt available.
Vendor Advisorylists.debian.orgMay 9, 2022, 8:15 AM- https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/blog.sonarsource.com
No excerpt available.
Exploitblog.sonarsource.comMay 9, 2022, 8:15 AM - http://packetstormsecurity.com/files/167989/Zimbra-UnRAR-Path-Traversal.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comMay 9, 2022, 8:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-41072CVSS 8.1 · High
squashfs_opendir in unsquash-2.c in Squashfs-Tools 4.5 allows Directory Traversal, a different vulnerability than CVE-2021-40153. A squashfs filesystem that has been crafted to in…
- CVE-2021-37712CVSS 8.2 · High
The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims t…
- CVE-2021-37701CVSS 8.2 · High
The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to…
- CVE-2020-36193CVSS 7.5 · High
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
- CVE-2020-11736CVSS 3.9 · Low
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a dire…
- CVE-2019-3902CVSS 5.1 · Medium
A flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and write files outside a repository.