Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-36241

Опубликовано: 05 фев. 2021
Источник: debian
EPSS Низкий

Описание

autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
gnome-autoarfixed0.2.4-3package
gnome-autoarno-dsabusterpackage
gnome-autoarno-dsastretchpackage

Примечания

  • Fixed by: https://gitlab.gnome.org/GNOME/gnome-autoar/-/commit/adb067e645732fdbe7103516e506d09eb6a54429

  • https://gitlab.gnome.org/GNOME/gnome-autoar/-/issues/7

  • Regression fix: https://gitlab.gnome.org/GNOME/gnome-autoar/-/commit/cc4e8b7ccc973ac69d75a7423fbe1bcdc51e2cb3

  • When fixing the issue make sure to apply as well the followup fix:

  • https://gitlab.gnome.org/GNOME/gnome-autoar/-/commit/8109c368c6cfdb593faaf698c2bf5da32bb1ace4

  • to not open CVE-2021-28650.

EPSS

Процентиль: 40%
0.00175
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 4 лет назад

autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

CVSS3: 3.9
redhat
почти 5 лет назад

autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

CVSS3: 5.5
nvd
больше 4 лет назад

autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

suse-cvrf
больше 4 лет назад

Security update for gnome-autoar

suse-cvrf
больше 4 лет назад

Security update for gnome-autoar

EPSS

Процентиль: 40%
0.00175
Низкий