UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile).
{ "binaries": [ { "binary_name": "unrar", "binary_version": "1:5.3.2-1+deb9u1build0.16.04.1" } ] }
{ "binaries": [ { "binary_name": "unrar", "binary_version": "1:5.5.8-1" } ] }