Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jj2q-v22w-qp64

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.9

Описание

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

EPSS

Процентиль: 19%
0.0006
Низкий

3.9 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 3.9
ubuntu
больше 5 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

CVSS3: 3.9
redhat
больше 5 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

CVSS3: 3.9
nvd
больше 5 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

CVSS3: 3.9
debian
больше 5 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Dir ...

suse-cvrf
больше 5 лет назад

Security update for file-roller

EPSS

Процентиль: 19%
0.0006
Низкий

3.9 Low

CVSS3

Дефекты

CWE-22