CVE-2017-20006
HIGH7.8EPSS 0.36%Published: 7/1/2021Modified: 4/28/2026
Description
UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile).
Affected packages (1)
- Debian/unrar-nonfreefrom 0, < 1:5.6.6-1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.8 | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |