Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xf7f-5p7r-xc3c

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 3.9

Описание

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

EPSS

Процентиль: 42%
0.00198
Низкий

3.9 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 3.9
ubuntu
больше 4 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

CVSS3: 3.9
redhat
больше 4 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

CVSS3: 3.9
nvd
больше 4 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

CVSS3: 3.9
debian
больше 4 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used b ...

suse-cvrf
7 месяцев назад

Security update for file-roller

EPSS

Процентиль: 42%
0.00198
Низкий

3.9 Low

CVSS3

Дефекты

CWE-22