It's not clear to me. It's not clear if it's just the WinRAR GUI that is exposed. It has to do with recovery volume processing which are seldom used on usenet. Newsbin ignores the recovery volumes and you'd have to manually download them. PARs are what's used instead of recovery volumes. The security report says it requires some manual intervention on the user part to trigger the execution which isn't possible in Newsbin so, again I'm not sure.
I downloaded the latest WinRAR source from RARLabs. It's got an older date than the GUI WinRAR which has the fix.
The latest beta
doesn't use WinRAR by default. Instead it uses 7zip to decode rars.
I'm still looking at it.
"A security issue involving out of bounds write is fixed in RAR4 recovery volumes processing code," the maintainers of the software said.