Debian Package Tracker
Register | Log in
Subscribe

rar

Archiver for .rar files

Choose email to subscribe with

general
  • source: rar (non-free)
  • version: 2:7.23-1
  • maintainer: Martin Meredith (DMD) (LowNMU)
  • uploaders: Bastian Germann [DMD]
  • arch: amd64
  • std-ver: 3.9.8
  • VCS: unknown
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2:6.23-1~deb11u1
  • oldstable: 2:7.01-1~deb12u1
  • stable: 2:7.11-1
  • testing: 2:7.23-1
  • unstable: 2:7.23-1
versioned links
  • 2:6.23-1~deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2:7.01-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2:7.11-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2:7.23-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • rar
action needed
A new upstream version is available: 723 high
A new upstream version 723 is available, you should consider packaging it.
Created: 2025-08-22 Last update: 2026-08-27 21:31
2 security issues in bullseye high

There are 2 open security issues in bullseye.

1 important issue:
  • CVE-2026-14191: An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is processed; subsequent .rev files supply an independent RecNum value that is validated against that file's own TotalCount field but never against the actual size of RecItems. A crafted set of two or more .rev files can therefore write an attacker-controlled 32-bit value (the header's RevCRC field) to RecItems[RecNum] at an attacker-controlled offset up to 65534 * sizeof(RecVolItem) bytes past the allocation, corrupting adjacent heap objects. Triggering requires the victim to run a recovery/test operation on an attacker-supplied .rev set (for example 'unrar t x.part1.rev', WinRAR 'Repair archive', or auto-recovery when extracting a volume set with a missing .rar part). This is the RAR5-path sibling of CVE-2023-40477 (which was fixed in the RAR3 path only in WinRAR 6.23). Fixed in WinRAR / RAR 7.23.
1 issue postponed or untriaged:
  • CVE-2024-33899: (needs triaging) RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen output, or cause a denial of service, via ANSI escape sequences.
Created: 2026-08-13 Last update: 2026-08-13 16:30
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-14191: An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is processed; subsequent .rev files supply an independent RecNum value that is validated against that file's own TotalCount field but never against the actual size of RecItems. A crafted set of two or more .rev files can therefore write an attacker-controlled 32-bit value (the header's RevCRC field) to RecItems[RecNum] at an attacker-controlled offset up to 65534 * sizeof(RecVolItem) bytes past the allocation, corrupting adjacent heap objects. Triggering requires the victim to run a recovery/test operation on an attacker-supplied .rev set (for example 'unrar t x.part1.rev', WinRAR 'Repair archive', or auto-recovery when extracting a volume set with a missing .rar part). This is the RAR5-path sibling of CVE-2023-40477 (which was fixed in the RAR3 path only in WinRAR 6.23). Fixed in WinRAR / RAR 7.23.
Created: 2026-08-13 Last update: 2026-08-13 16:30
Standards version of the package is outdated. high
The package is severely out of date with respect to the Debian Policy. The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 3.9.8).
Created: 2017-08-29 Last update: 2026-07-07 21:20
lintian reports 3 warnings normal
Lintian reports 3 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2026-07-08 Last update: 2026-07-08 10:48
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-14191: (needs triaging) An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecItems vector is sized only when the first .rev file in a set is processed; subsequent .rev files supply an independent RecNum value that is validated against that file's own TotalCount field but never against the actual size of RecItems. A crafted set of two or more .rev files can therefore write an attacker-controlled 32-bit value (the header's RevCRC field) to RecItems[RecNum] at an attacker-controlled offset up to 65534 * sizeof(RecVolItem) bytes past the allocation, corrupting adjacent heap objects. Triggering requires the victim to run a recovery/test operation on an attacker-supplied .rev set (for example 'unrar t x.part1.rev', WinRAR 'Repair archive', or auto-recovery when extracting a volume set with a missing .rar part). This is the RAR5-path sibling of CVE-2023-40477 (which was fixed in the RAR3 path only in WinRAR 6.23). Fixed in WinRAR / RAR 7.23.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-08-13 Last update: 2026-08-13 16:30
news
[rss feed]
  • [2026-07-13] rar 2:7.23-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-07] Accepted rar 2:7.23-1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2026-05-10] rar 2:7.22-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-04] Accepted rar 2:7.22-1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2026-02-24] rar 2:7.20-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-17] Accepted rar 2:7.20-1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2025-08-16] rar 2:7.12-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-10] Accepted rar 2:7.12-1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2025-07-05] Accepted rar 2:7.01-1~deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Adrian Bunk)
  • [2025-04-01] rar 2:7.11-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-27] Accepted rar 2:7.11-1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2025-03-20] rar 2:7.10-2 MIGRATED to testing (Debian testing watch)
  • [2025-03-14] Accepted rar 2:7.10-2 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2025-03-01] rar 2:7.10-1 MIGRATED to testing (Debian testing watch)
  • [2025-02-23] Accepted rar 2:7.10-1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2024-11-30] rar 2:7.10~b1-2 MIGRATED to testing (Debian testing watch)
  • [2024-11-24] Accepted rar 2:7.10~b1-2 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2024-11-13] Accepted rar 2:7.10~b1-1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2024-09-22] rar 2:7.01-1 MIGRATED to testing (Debian testing watch)
  • [2024-09-16] Accepted rar 2:7.01-1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2024-03-11] rar 2:7.00-1 MIGRATED to testing (Debian testing watch)
  • [2024-03-04] Accepted rar 2:7.00-1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2023-09-09] Accepted rar 2:6.23-1~deb11u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2023-09-09] Accepted rar 2:6.20-0.1~deb11u1 (source) into oldstable-proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2023-08-27] Accepted rar 2:6.23-1~deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Markus Koschany)
  • [2023-08-27] Accepted rar 2:6.23-1~deb10u1 (source) into oldoldstable (Markus Koschany)
  • [2023-08-22] rar 2:6.23-1 MIGRATED to testing (Debian testing watch)
  • [2023-08-17] Accepted rar 2:6.20-0.1~deb10u1 (source amd64) into oldoldstable (Markus Koschany)
  • [2023-08-16] Accepted rar 2:6.23-1 (source) into unstable (Bastian Germann) (signed by: bage@debian.org)
  • [2023-02-12] rar 2:6.20-0.1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian (0, 3)
  • buildd: logs, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • screenshots
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2:7.23-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing