Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a … (triple dot) in the filename of the ZIP file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Winrar | Rarlab | 3.0.0 (including) | 3.0.0 (including) |
Winrar | Rarlab | 3.10 (including) | 3.10 (including) |
Winrar | Rarlab | 3.10_beta3 (including) | 3.10_beta3 (including) |
Winrar | Rarlab | 3.10_beta5 (including) | 3.10_beta5 (including) |
Winrar | Rarlab | 3.11 (including) | 3.11 (including) |
Winrar | Rarlab | 3.20 (including) | 3.20 (including) |
Winrar | Rarlab | 3.40 (including) | 3.40 (including) |
Winrar | Rarlab | 3.41 (including) | 3.41 (including) |
Winrar | Rarlab | 3.42 (including) | 3.42 (including) |