Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-36314

Опубликовано: 15 фев. 2021
Источник: redhat
CVSS3: 3.9
EPSS Низкий

Описание

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

A path traversal vulnerability was found in file-roller due to an incomplete fix for CVE-2020-11736. It may still be possible to extract files outside of the intended directory in case of malicious archives containing symbolic links. The highest threat from this vulnerability is to data integrity and system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6file-rollerOut of support scope
Red Hat Enterprise Linux 7file-rollerOut of support scope
Red Hat Enterprise Linux 8file-rollerFixedRHSA-2021:417909.11.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1947534file-roller: directory traversal via directory symlink pointing outside of the target directory (incomplete fix for CVE-2020-11736)

EPSS

Процентиль: 42%
0.00198
Низкий

3.9 Low

CVSS3

Связанные уязвимости

CVSS3: 3.9
ubuntu
больше 4 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

CVSS3: 3.9
nvd
больше 4 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

CVSS3: 3.9
debian
больше 4 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used b ...

suse-cvrf
12 месяцев назад

Security update for file-roller

rocky
около 4 лет назад

Low: file-roller security update

EPSS

Процентиль: 42%
0.00198
Низкий

3.9 Low

CVSS3