Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-36314

Опубликовано: 07 апр. 2021
Источник: debian

Описание

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
file-rollerfixed3.38.1-1package
file-rollerno-dsabusterpackage
file-rollerpostponedstretchpackage

Примечания

  • https://gitlab.gnome.org/GNOME/file-roller/-/commit/e970f4966bf388f6e7c277357c8b186c645683ae

  • https://gitlab.gnome.org/GNOME/file-roller/-/issues/108

Связанные уязвимости

CVSS3: 3.9
ubuntu
больше 4 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

CVSS3: 3.9
redhat
больше 4 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

CVSS3: 3.9
nvd
больше 4 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

suse-cvrf
7 месяцев назад

Security update for file-roller

rocky
больше 3 лет назад

Low: file-roller security update