漏洞描述
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
research.checkpoint.comhttps://research.checkpoint.com/extracting-code-execution-from-winrar/↗packetstormsecurity.comhttp://packetstormsecurity.com/files/152618/RARLAB-WinRAR-ACE-Format-Input-Validation-Remote-Code-Execution.html↗github.comhttps://github.com/blau72/CVE-2018-20250-WinRAR-ACE↗www.securityfocus.comhttp://www.securityfocus.com/bid/106948↗www.win-rar.comhttps://www.win-rar.com/whatsnew.html↗