🛡️ SUSE-SU-2021:2834-1 — unrar (CVE-2017-12938 +5 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for unrar

This update for unrar to version 5.6.1 fixes several issues.

These security issues were fixed:

  • CVE-2017-12938: Prevent remote attackers to bypass a directory-traversal

protection mechanism via vectors involving a symlink to the . directory, a

symlink to the .. directory, and a regular file (bsc#1054038).

  • CVE-2017-12940: Prevent out-of-bounds read in the EncodeFileName::Decode call

within the Archive::ReadHeader15 function (bsc#1054038).

  • CVE-2017-12941: Prevent an out-of-bounds read in the Unpack::Unpack20

function (bsc#1054038).

  • CVE-2017-12942: Prevent a buffer overflow in the Unpack::LongLZ function

(bsc#1054038).

  • CVE-2017-20006: Fixed heap-based buffer overflow in Unpack:CopyString (bsc#1187974).

These non-security issues were fixed:

  • Added extraction support for .LZ archives created by Lzip compressor
  • Enable unpacking of files in ZIP archives compressed with XZ algorithm and

encrypted with AES

  • Added support for PAX extended headers inside of TAR archive
  • If RAR recovery volumes (.rev files) are present in the same folder as usual

RAR volumes, archive test command verifies .rev contents after completing

testing .rar files

  • By default unrar skips symbolic links with absolute paths in link target when

extracting unless -ola command line switch is specified

  • Added support for AES-NI CPU instructions
  • Support for a new RAR 5.0 archiving format
  • Wildcard exclusion mask for folders
  • Prevent conditional jumps depending on uninitialised values (bsc#1046882)

Affected software

SUSE-SU-2021:2834-1 is recorded against 1 package.

  • unrar (fixed in 5.6.1-4.5.1)

Timeline and source

Published on 25 August 2021 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2021-08-25
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
unrar 5.6.1-4.5.1

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2021:2834-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2021:2834-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSE