Debian Package Tracker
Register | Log in
Subscribe

unrar-nonfree

Choose email to subscribe with

general
  • source: unrar-nonfree (non-free)
  • version: 1:7.2.7-1
  • maintainer: UnRar maintainer team (DMD)
  • uploaders: Martin Meredith [DMD] – Norbert Preining [DMD] – YOKOTA Hiroshi [DMD] [DM]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1:6.0.3-1+deb11u3
  • oldstable: 1:6.2.6-1+deb12u1
  • stable: 1:7.1.8-1
  • testing: 1:7.2.7-1
  • unstable: 1:7.2.7-1
versioned links
  • 1:6.0.3-1+deb11u3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:6.2.6-1+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:7.1.8-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1:7.2.7-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libunrar-dev
  • libunrar-headers
  • libunrar5t64
  • unrar
action needed
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-14191: An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is processed; subsequent .rev files supply an independent RecNum value that is validated against that file's own TotalCount field but never against the actual size of RecItems. A crafted set of two or more .rev files can therefore write an attacker-controlled 32-bit value (the header's RevCRC field) to RecItems[RecNum] at an attacker-controlled offset up to 65534 * sizeof(RecVolItem) bytes past the allocation, corrupting adjacent heap objects. Triggering requires the victim to run a recovery/test operation on an attacker-supplied .rev set (for example 'unrar t x.part1.rev', WinRAR 'Repair archive', or auto-recovery when extracting a volume set with a missing .rar part). This is the RAR5-path sibling of CVE-2023-40477 (which was fixed in the RAR3 path only in WinRAR 6.23). Fixed in WinRAR / RAR 7.23.
Created: 2026-08-13 Last update: 2026-08-13 16:30
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-14191: An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is processed; subsequent .rev files supply an independent RecNum value that is validated against that file's own TotalCount field but never against the actual size of RecItems. A crafted set of two or more .rev files can therefore write an attacker-controlled 32-bit value (the header's RevCRC field) to RecItems[RecNum] at an attacker-controlled offset up to 65534 * sizeof(RecVolItem) bytes past the allocation, corrupting adjacent heap objects. Triggering requires the victim to run a recovery/test operation on an attacker-supplied .rev set (for example 'unrar t x.part1.rev', WinRAR 'Repair archive', or auto-recovery when extracting a volume set with a missing .rar part). This is the RAR5-path sibling of CVE-2023-40477 (which was fixed in the RAR3 path only in WinRAR 6.23). Fixed in WinRAR / RAR 7.23.
Created: 2026-08-13 Last update: 2026-08-13 16:30
2 security issues in bullseye high

There are 2 open security issues in bullseye.

1 important issue:
  • CVE-2026-14191: An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is processed; subsequent .rev files supply an independent RecNum value that is validated against that file's own TotalCount field but never against the actual size of RecItems. A crafted set of two or more .rev files can therefore write an attacker-controlled 32-bit value (the header's RevCRC field) to RecItems[RecNum] at an attacker-controlled offset up to 65534 * sizeof(RecVolItem) bytes past the allocation, corrupting adjacent heap objects. Triggering requires the victim to run a recovery/test operation on an attacker-supplied .rev set (for example 'unrar t x.part1.rev', WinRAR 'Repair archive', or auto-recovery when extracting a volume set with a missing .rar part). This is the RAR5-path sibling of CVE-2023-40477 (which was fixed in the RAR3 path only in WinRAR 6.23). Fixed in WinRAR / RAR 7.23.
1 issue postponed or untriaged:
  • CVE-2024-33899: (needs triaging) RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences.
Created: 2026-08-13 Last update: 2026-08-13 16:30
2 security issues in bookworm high

There are 2 open security issues in bookworm.

1 important issue:
  • CVE-2026-14191: An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is processed; subsequent .rev files supply an independent RecNum value that is validated against that file's own TotalCount field but never against the actual size of RecItems. A crafted set of two or more .rev files can therefore write an attacker-controlled 32-bit value (the header's RevCRC field) to RecItems[RecNum] at an attacker-controlled offset up to 65534 * sizeof(RecVolItem) bytes past the allocation, corrupting adjacent heap objects. Triggering requires the victim to run a recovery/test operation on an attacker-supplied .rev set (for example 'unrar t x.part1.rev', WinRAR 'Repair archive', or auto-recovery when extracting a volume set with a missing .rar part). This is the RAR5-path sibling of CVE-2023-40477 (which was fixed in the RAR3 path only in WinRAR 6.23). Fixed in WinRAR / RAR 7.23.
1 ignored issue:
  • CVE-2024-33899: RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences.
Created: 2026-08-13 Last update: 2026-08-13 16:30
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-14191: (needs triaging) An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is processed; subsequent .rev files supply an independent RecNum value that is validated against that file's own TotalCount field but never against the actual size of RecItems. A crafted set of two or more .rev files can therefore write an attacker-controlled 32-bit value (the header's RevCRC field) to RecItems[RecNum] at an attacker-controlled offset up to 65534 * sizeof(RecVolItem) bytes past the allocation, corrupting adjacent heap objects. Triggering requires the victim to run a recovery/test operation on an attacker-supplied .rev set (for example 'unrar t x.part1.rev', WinRAR 'Repair archive', or auto-recovery when extracting a volume set with a missing .rar part). This is the RAR5-path sibling of CVE-2023-40477 (which was fixed in the RAR3 path only in WinRAR 6.23). Fixed in WinRAR / RAR 7.23.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-08-13 Last update: 2026-08-13 16:30
news
[rss feed]
  • [2026-07-07] unrar-nonfree 1:7.2.7-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-03] Accepted unrar-nonfree 1:7.2.7-1 (source) into unstable (YOKOTA Hiroshi)
  • [2026-05-14] unrar-nonfree 1:7.2.6-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-30] Accepted unrar-nonfree 1:7.2.6-1 (source) into unstable (YOKOTA Hiroshi)
  • [2026-04-14] unrar-nonfree 1:7.2.5-2 MIGRATED to testing (Debian testing watch)
  • [2026-04-11] Accepted unrar-nonfree 1:7.2.5-2 (source) into unstable (YOKOTA Hiroshi)
  • [2026-03-29] unrar-nonfree 1:7.2.5-1 MIGRATED to testing (Debian testing watch)
  • [2026-03-24] Accepted unrar-nonfree 1:7.2.5-1 (source) into unstable (YOKOTA Hiroshi)
  • [2026-02-08] unrar-nonfree 1:7.2.4-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-05] Accepted unrar-nonfree 1:7.2.4-1 (source) into unstable (YOKOTA Hiroshi)
  • [2025-12-30] unrar-nonfree 1:7.2.3-2 MIGRATED to testing (Debian testing watch)
  • [2025-12-27] Accepted unrar-nonfree 1:7.2.3-2 (source) into unstable (YOKOTA Hiroshi)
  • [2025-12-22] unrar-nonfree 1:7.2.3-1 MIGRATED to testing (Debian testing watch)
  • [2025-12-19] Accepted unrar-nonfree 1:7.2.3-1 (source) into unstable (YOKOTA Hiroshi)
  • [2025-11-23] unrar-nonfree 1:7.2.2-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-20] Accepted unrar-nonfree 1:7.2.2-1 (source) into unstable (YOKOTA Hiroshi)
  • [2025-11-02] unrar-nonfree 1:7.2.1-1 MIGRATED to testing (Debian testing watch)
  • [2025-10-30] Accepted unrar-nonfree 1:7.2.1-1 (source) into unstable (YOKOTA Hiroshi)
  • [2025-10-01] unrar-nonfree 1:7.1.10-3 MIGRATED to testing (Debian testing watch)
  • [2025-09-29] Accepted unrar-nonfree 1:7.1.10-3 (source) into unstable (YOKOTA Hiroshi)
  • [2025-08-25] unrar-nonfree 1:7.1.10-2 MIGRATED to testing (Debian testing watch)
  • [2025-08-23] Accepted unrar-nonfree 1:7.1.10-2 (source) into unstable (YOKOTA Hiroshi)
  • [2025-08-12] unrar-nonfree 1:7.1.10-1 MIGRATED to testing (Debian testing watch)
  • [2025-07-30] Accepted unrar-nonfree 1:7.1.10-1 (source) into unstable (YOKOTA Hiroshi)
  • [2025-07-25] Accepted unrar-nonfree 1:7.1.9-1 (source) into unstable (YOKOTA Hiroshi)
  • [2025-07-17] unrar-nonfree 1:7.1.8-1 MIGRATED to testing (Debian testing watch)
  • [2025-06-27] Accepted unrar-nonfree 1:7.1.8-1 (source) into unstable (YOKOTA Hiroshi)
  • [2025-06-10] Accepted unrar-nonfree 1:7.1.7-1 (source) into unstable (YOKOTA Hiroshi)
  • [2025-03-27] unrar-nonfree 1:7.1.6-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-24] Accepted unrar-nonfree 1:7.1.6-1 (source) into unstable (YOKOTA Hiroshi)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 1:7.2.7-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing