Vulnerability Details CVE-2014-9983
Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 49.4%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 4.3
Products affected by CVE-2014-9983
-
cpe:2.3:a:rarlab:rar:4.00
-
cpe:2.3:a:rarlab:rar:4.01
-
cpe:2.3:a:rarlab:rar:4.10
-
cpe:2.3:a:rarlab:rar:4.11
-
cpe:2.3:a:rarlab:rar:4.20
-
cpe:2.3:a:rarlab:rar:5.00
-
cpe:2.3:a:rarlab:rar:5.01
-
cpe:2.3:a:rarlab:rar:5.10
-
cpe:2.3:a:rarlab:rar:5.11
-
cpe:2.3:a:rarlab:rar:5.20
-
cpe:2.3:a:rarlab:rar:5.21
-
cpe:2.3:a:rarlab:rar:5.30
-
cpe:2.3:a:rarlab:rar:5.31
-
cpe:2.3:a:rarlab:rar:5.40
-
cpe:2.3:a:rarlab:rar:5.50