UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:rarlab:unrar:*:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"fixed": "6.2.3"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"fixed": "6.2.3"
}
]
}
]
}