How Unrar Handles Destination Symlinks
When extracting archives, unrar employs strict security
checks to determine how it interacts with symbolic links in the
destination path. This article examines how unrar validates
extraction paths, resolves pre-existing symlinks, mitigates path
traversal vulnerabilities (such as "Zip Slip"), and enforces security
boundaries to prevent unauthorized file overwrites.
Canonical Path Resolution and Jail Checks
Modern versions of unrar enforce extraction boundaries
to ensure that extracted contents remain strictly within the intended
destination directory. Before writing any file to disk, the utility
verifies the canonical path of the target location.
If the base destination path provided in the command line contains or
ends with a symlink, unrar typically resolves the symlink
to its target directory on the host filesystem and proceeds with
extraction, provided the user has write permissions in the target
location. However, problems arise when paths inside the archive
resolve through symlinks to locations outside the root extraction
folder.
Protection Against Arbitrary File Overwrites
Historically, archive utilities were vulnerable to directory
traversal attacks where an archive would create a symlink pointing to an
absolute path (such as /etc or /usr/bin),
followed by a standard file that wrote into that symlink path.
To mitigate this attack vector:
- Intermediate Symlink Validation: As
unrarcreates subdirectories and files, it inspects each path component. If a path segment points to a symlink that leads outside the extraction root,unrartreats the operation as insecure. - Refusal to Follow Traversal Links: If an archive contains a symlink pointing to an external directory, subsequent files in the archive that attempt to extract through that symlink path are blocked. The extraction will fail with an error or skip the affected files.
- Overwrite Protections: By default,
unrarwill not blindly follow an existing symlink to overwrite a target file outside the working directory tree unless explicit flags are supplied to permit overwriting.
Symlink Handling by Default Flags
The behavior of unrar also depends on how links are
encoded within the archive and which command-line switches are
invoked:
- Default Behavior: Symlinks stored within the archive are extracted as symbolic links on platforms that support them (such as Linux and macOS), assuming user permissions allow link creation.
- The
-olSwitch: Instructsunrarto save symbolic links as links rather than writing the contents of the files they reference. - Absolute Path Stripping: By default,
unrarstrips drive letters and leading path separators (such as/orC:\) to prevent archives from defining root-level destinations directly.
If a pre-existing symbolic link exists inside the extraction
directory prior to running the utility, unrar checks
whether writing through that link compromises the root boundary. If the
link points to a location outside the extraction target,
unrar detects the breakout attempt, halts writing to that
specific path, and reports an error to prevent potential system
compromise.