ELA-1494-1 unrar-nonfree security update

ANSI escape injection

2025-08-09
Packageunrar-nonfree
Version1:5.6.6-1+deb10u5~deb9u1 (stretch), 1:5.6.6-1+deb10u5 (buster)
Related CVEs CVE-2024-33899


ANSI escape injection has been fixed in UnRAR, an unarchiver for .rar archives.



For Debian 10 buster, these problems have been fixed in version 1:5.6.6-1+deb10u5.

For Debian 9 stretch, these problems have been fixed in version 1:5.6.6-1+deb10u5~deb9u1.

We recommend that you upgrade your unrar-nonfree packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.