Directory traversal vulnerability in the -x (extract) command line option in unarj allows remote attackers to overwrite arbitrary files via an arj archive with filenames that contain .. (dot dot) sequences.
| Software | From | Fixed in |
|---|---|---|
| gentoo / linux | - | - |
| arjsoftware / unarj | 2.62 | 2.62.x |
| arjsoftware / unarj | 2.63-a | 2.63-a.x |
| arjsoftware / unarj | 2.64 | 2.64.x |
| arjsoftware / unarj | 2.65 | 2.65.x |
| debian / debian_linux | 3.0 | 3.0.x |