Directory traversal vulnerability in WinRAR 3.42 and earlier, when the user clicks on the ZIP file to extract it, allows remote attackers to create arbitrary files via a ... (triple dot) in the filename of the ZIP file.
https://exchange.xforce.ibmcloud.com/vulnerabilities/20585
https://euvd.enisa.europa.eu/vulnerability/EUVD-2005-0332