ARC 5.21q allows directory traversal via a full pathname in an archive file.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2015-9117
https://bugzilla.redhat.com/show_bug.cgi?id=1179142
https://bugs.debian.org/774527
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00048.html