Debian Security Advisory
DLA-2567-1 unrar-free -- LTS security update
- Date Reported:
- 18 Feb 2021
- Affected Packages:
- unrar-free
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2017-14120, CVE-2017-14121, CVE-2017-14122.
- More information:
-
Several issues have been found in unrar-free, an unarchiver for .rar files.
- CVE-2017-14120
This CVE is related to a directory traversal vulnerability for RAR v2 archives.
- CVE-2017-14121
This CVE is related to NULL pointer dereference flaw triggered by a specially crafted RAR archive.
- CVE-2017-14122
This CVE is related to stack-based buffer over-read.
For Debian 9 stretch, these problems have been fixed in version 1:0.0.1+cvs20140707-1+deb9u1.
We recommend that you upgrade your unrar-free packages.
For the detailed security status of unrar-free please refer to its security tracker page at: https://security-tracker.debian.org/tracker/unrar-free
Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
- CVE-2017-14120