CVE-2025-60835
Published: July 22nd, 2026
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
HIGH
CVSS v3: 7.8
CVSS v3: 7.8
Status
| DocFilters Release | Package | State | Justification | Comment |
|---|---|---|---|---|
| 26.3 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 26.2 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 26.1 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 25.4 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 25.3 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 25.2 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 25.1 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 24.4 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 24.4.0 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 24.3 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 24.2 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 24.1 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 23.3 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 23.2 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 23.1 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 22.4 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 22.3 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 22.2 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 22.1 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 21.11 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 21.8 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 21.5.0 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 21.2.0 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 11.4.19.3667 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 11.4.18.3599 | unrar (5.9.1) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 11.4.16.3445 | unrar (5.3.9) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 11.4.15.3368 | unrar (5.3.9) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 11.4.14.3263 | unrar (5.3.9) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 11.4.13.3179 | unrar (5.3.9) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 11.4.12.3054 | unrar (5.3.9) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 11.4.11.3040 | unrar (5.3.9) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 11.4.11.2990 | unrar (5.3.9) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 11.4.10.2934 | unrar (5.3.9) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 11.4.9.2878 | unrar (5.3.9) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
| 11.4.8.2822 | unrar (5.3.9) | Not Affected | Code Not Present | This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue. |
Severity score breakdown
Attack Complexity
LOW
Attack Vector
LOCAL
Availability Impact
HIGH
Base Score
7.8
Base Severity
HIGH
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
REQUIRED
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Version
3.1