Loading
RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
Use CWE-22, Rarlab vendor hub and Unrar product page to widen CVE-2022-30333 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-12942, CVE-2017-12941 and CVE-2017-12940 for nearby disclosures in the same product family.