CVE-2014-9983: RARLAB Rar

Medium severity, CVSS 5.5. EPSS: 1.8% chance of exploitation in the next 30 days.

Directory Traversal exists in RAR 4.x and 5.x because an unpack operation follows any symlinks, including symlinks contained in the archive. This allows remote attackers to write to arbitrary files via a crafted archive.

Affected products

  • RARLAB Rar: version 4.00 only; version 4.01 only; version 4.10 only; version 4.11 only; version 4.20 only; version 5.00 only; …

Published 2017-06-04. Last modified 2026-06-17.