High severity7.5NVD Advisory· Published Sep 3, 2017· Updated May 13, 2026
CVE-2017-14120
CVE-2017-14120
Description
unrar 0.0.1 (aka unrar-free or unrar-gpl) suffers from a directory traversal vulnerability for RAR v2 archives: pathnames of the form ../[filename] are unpacked into the upper directory.
Affected products
2- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.openwall.com/lists/oss-security/2017/08/20/1nvdMailing ListThird Party Advisory
- bugs.debian.org/874059nvdIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2021/02/msg00026.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.