UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile).
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-20006.json"