CVE-2025-60835

Published: July 22nd, 2026
An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
HIGH
CVSS v3: 7.8

Status

DocFilters Release Package State Justification Comment
26.3 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
26.2 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
26.1 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
25.4 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
25.3 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
25.2 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
25.1 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
24.4 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
24.4.0 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
24.3 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
24.2 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
24.1 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
23.3 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
23.2 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
23.1 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
22.4 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
22.3 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
22.2 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
22.1 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
21.11 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
21.8 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
21.5.0 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
21.2.0 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
11.4.19.3667 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
11.4.18.3599 unrar (5.9.1) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
11.4.16.3445 unrar (5.3.9) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
11.4.15.3368 unrar (5.3.9) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
11.4.14.3263 unrar (5.3.9) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
11.4.13.3179 unrar (5.3.9) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
11.4.12.3054 unrar (5.3.9) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
11.4.11.3040 unrar (5.3.9) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
11.4.11.2990 unrar (5.3.9) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
11.4.10.2934 unrar (5.3.9) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
11.4.9.2878 unrar (5.3.9) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.
11.4.8.2822 unrar (5.3.9) Not Affected Code Not Present This CVE is against IZArc (a third-party Windows GUI archive manager by Ivan Zahariev), not the RARLab UnRAR library. The vulnerable ‘unrar.dll’ referenced in the advisory is IZArc’s own bundled extraction component and its ADS-validation logic during extraction-to-disk, which is entirely separate application code that Document Filters does not vendor, build, or link (no IZArc references anywhere in the codebase). Document Filters vendors only the official RARLab UnRAR source (unrarsrc-5.9.1.tar.gz). Independently, Document Filters never extracts RAR entries to disk paths at all: filters/isysreaders/readers/ReaderRAR.cpp drives unrar exclusively via RAROpenArchiveEx + RARProcessFileW(RAR_TEST) with a callback that streams entry data into an in-memory CTemporaryStream, so there is no path-traversal surface in our RAR handling regardless of the IZArc issue.

Severity score breakdown

Attack Complexity
LOW
Attack Vector
LOCAL
Availability Impact
HIGH
Base Score
7.8
Base Severity
HIGH
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Privileges Required
NONE
Scope
UNCHANGED
User Interaction
REQUIRED
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Version
3.1

References