Loading
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] are unpacked into the upper directory.
Use CWE-22, Rarlab vendor hub and Unrar product page to widen CVE-2017-14120 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-30333, CVE-2017-12942 and CVE-2017-12941 for nearby disclosures in the same product family.