Security Vulnerabilities Found in UnRAR
UnRAR, the standard extraction utility for RAR archives, has historically been subject to various high-severity security vulnerabilities, ranging from directory traversal to remote code execution. Because archive extractors often parse untrusted input automatically within email gateways, antivirus systems, and web servers, flaws in UnRAR's underlying C++ parsing engine have frequently exposed systems to severe exploitation. This overview details the primary classes of historical vulnerabilities discovered in UnRAR, specific notable Common Vulnerabilities and Exposures (CVEs), and their operational impact.
Path Traversal and Arbitrary File Write
The most prevalent and impactful vulnerabilities in UnRAR relate to path traversal. Archive formats allow files to specify relative storage paths; if an extractor does not strictly sanitize these paths, an attacker can write or overwrite arbitrary files on the victim's filesystem.
- CVE-2022-30333: A critical path traversal flaw
discovered in the Unix version of UnRAR prior to version 6.12. An
attacker could craft a malicious RAR archive with relative directory
paths (such as
../) to extract files outside the intended extraction folder. This vulnerability achieved remote code execution when targeted against automated systems, most notably Zimbra Collaboration mail servers, by overwriting system files or dropping malicious JSP shells into web-accessible directories.
Buffer and Memory Corruptions
Parsing compressed data requires complex algorithms for formats like PPMd and custom dictionary structures. Implementations within UnRAR have frequently suffered from memory management bugs, including out-of-bounds reads and writes.
- CVE-2023-40477: An out-of-bounds write flaw in
UnRAR and WinRAR's processing of recovery volumes (
.revfiles). The vulnerability resulted from a lack of proper memory validation when handling recovery records, allowing an attacker to trigger an out-of-bounds write, potentially leading to arbitrary code execution if a user opened or extracted a specially crafted volume. - CVE-2007-0855: An earlier stack-based buffer overflow in UnRAR's command-line parsing utility. The extractor failed to handle overly long filenames or password fields, allowing memory overwrites that crashed the application or executed arbitrary code with the user's privileges.
Denial of Service via Algorithmic Complexity and Malformed Headers
UnRAR has also encountered several Denial of Service (DoS) flaws resulting from infinite loops, null-pointer dereferences, and uncaught parsing exceptions.
- Malformed Archive Headers: Several historical issues involved malformed archive headers (such as invalid main headers or corrupted block sizes) that caused the extraction engine to enter infinite loops or crash due to null-pointer dereferences. While not resulting in code execution, these bugs effectively disabled automated file-scanning pipelines and mail filters processing inbound attachments.
Attack Vector Implications
Because UnRAR is widely embedded into automated enterprise infrastructure (such as mail transport agents, file storage solutions, and network-attached storage firmware), these vulnerabilities rarely require active user interaction when deployed server-side. Once a malicious archive enters the pipeline, the automated background worker triggers the parsing logic, inheriting the permissions of the service running the binary. Modern mitigations require strictly sandboxing extraction services, running processes with least privilege, and regularly updating the UnRAR library to patched releases.