UnRAR 5.6.1.2 and 5.6.1.3 has a heap-based buffer overflow in Unpack::CopyString (called from Unpack::Unpack5 and CmdExtract::ExtractCurrentFile).
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1:5.6.6-2build1", "binary_name": "libunrar-dev" }, { "binary_version": "1:5.6.6-2build1", "binary_name": "libunrar5" }, { "binary_version": "1:5.6.6-2build1", "binary_name": "unrar" } ] }