Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
CVE-2022-48579
See a problem?
Please try reporting it
to the source
first.
Source
https://nvd.nist.gov/vuln/detail/CVE-2022-48579
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-48579.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2022-48579
Downstream
DEBIAN-CVE-2022-48579
DLA-3535-1
UBUNTU-CVE-2022-48579
USN-7350-1
Published
2023-08-07T04:15:12Z
Modified
2025-10-15T04:35:25Z
Severity
7.5 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Calculator
Summary
[none]
Details
UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.
References
https://github.com/pmachapman/unrar/commit/2ecab6bb5ac4f3b88f270218445496662020205f#diff-ca3086f578522062d7e390ed2cd7e10f646378a8b8cbf287a6e4db5966df68ee
https://lists.debian.org/debian-lts-announce/2023/08/msg00023.html
Affected packages
Git
/
github.com/pmachapman/unrar
Affected ranges
Type
GIT
Repo
https://github.com/pmachapman/unrar
Events
Introduced
0
Unknown introduced commit / All previous commits are affected
Fixed
2ecab6bb5ac4f3b88f270218445496662020205f
CVE-2022-48579 - OSV