Directory traversal vulnerability
| Affects | Status | Importance | Assigned to | Milestone | |
|---|---|---|---|---|---|
| | unrar-nonfree (Debian) |
Fix Released
|
Unknown
|
||
| | unrar-nonfree (Ubuntu) |
Undecided
|
Unassigned | ||
| | Precise |
Undecided
|
Steve Beattie | ||
| | Trusty |
Undecided
|
Steve Beattie | ||
| | Utopic |
Undecided
|
Steve Beattie | ||
Bug Description
unrar-nonfree before version 5.2.7 suffers from a symlink directory traversal vulnerability.
More details at:
https:/
| Changed in unrar-nonfree (Ubuntu): | |
| status: | New → Fix Released |
| Felix Geyer (debfx) wrote : | #1 |
| Felix Geyer (debfx) wrote : | #2 |
| Felix Geyer (debfx) wrote : | #3 |
| Felix Geyer (debfx) wrote : | #4 |
| Steve Beattie (sbeattie) wrote : | #5 |
Thanks, I'll take a look at these in a bit.
| Changed in unrar-nonfree (Ubuntu Precise): | |
| status: | New → In Progress |
| Changed in unrar-nonfree (Ubuntu Trusty): | |
| status: | New → In Progress |
| Changed in unrar-nonfree (Ubuntu Utopic): | |
| status: | New → In Progress |
| Changed in unrar-nonfree (Ubuntu Precise): | |
| assignee: | nobody → Steve Beattie (sbeattie) |
| Changed in unrar-nonfree (Ubuntu Trusty): | |
| assignee: | nobody → Steve Beattie (sbeattie) |
| Changed in unrar-nonfree (Ubuntu Utopic): | |
| assignee: | nobody → Steve Beattie (sbeattie) |
| Launchpad Janitor (janitor) wrote : | #6 |
This bug was fixed in the package unrar-nonfree - 1:5.0.10-
---------------
unrar-nonfree (1:5.0.
* SECURITY UPDATE: symlink directory traversal vulnerability (LP: #1451260)
- debian/
-- Felix Geyer <email address hidden> Sun, 03 May 2015 22:57:02 +0200
| Changed in unrar-nonfree (Ubuntu Utopic): | |
| status: | In Progress → Fix Released |
| Launchpad Janitor (janitor) wrote : | #7 |
This bug was fixed in the package unrar-nonfree - 1:4.0.3-1ubuntu0.1
---------------
unrar-nonfree (1:4.0.
* SECURITY UPDATE: symlink directory traversal vulnerability (LP: #1451260)
- debian/
-- Felix Geyer <email address hidden> Sun, 03 May 2015 23:09:30 +0200
| Changed in unrar-nonfree (Ubuntu Precise): | |
| status: | In Progress → Fix Released |
| Launchpad Janitor (janitor) wrote : | #8 |
This bug was fixed in the package unrar-nonfree - 1:5.0.10-
---------------
unrar-nonfree (1:5.0.
* SECURITY UPDATE: symlink directory traversal vulnerability (LP: #1451260)
- debian/
-- Felix Geyer <email address hidden> Sun, 03 May 2015 22:57:02 +0200
| Changed in unrar-nonfree (Ubuntu Trusty): | |
| status: | In Progress → Fix Released |
| Changed in unrar-nonfree (Debian): | |
| status: | Unknown → Fix Released |


I'm not aware of any CVE for this issue.
Attached are debdiffs for precise, trusty and utopic.
vivid has 5.2.7, so not affected.