Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-36314

Опубликовано: 15 фев. 2021
Источник: redhat
CVSS3: 3.9

Описание

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

A path traversal vulnerability was found in file-roller due to an incomplete fix for CVE-2020-11736. It may still be possible to extract files outside of the intended directory in case of malicious archives containing symbolic links. The highest threat from this vulnerability is to data integrity and system availability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6file-rollerOut of support scope
Red Hat Enterprise Linux 7file-rollerOut of support scope
Red Hat Enterprise Linux 8file-rollerFixedRHSA-2021:417909.11.2021

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1947534file-roller: directory traversal via directory symlink pointing outside of the target directory (incomplete fix for CVE-2020-11736)

3.9 Low

CVSS3

Связанные уязвимости

CVSS3: 3.9
ubuntu
больше 4 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

CVSS3: 3.9
nvd
больше 4 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

CVSS3: 3.9
debian
больше 4 лет назад

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used b ...

suse-cvrf
7 месяцев назад

Security update for file-roller

rocky
больше 3 лет назад

Low: file-roller security update

3.9 Low

CVSS3