An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade file-roller | May 4, 2022 | Sep 21, 2019 |
| Centos_linux | — | Upgrade file-roller-debugsourceUpgrade file-rollerUpgrade file-roller-debuginfo | Nov 5, 2020 | Sep 21, 2019 |
| Debian | — | Upgrade file-roller | Sep 30, 2019 | Sep 21, 2019 |
| Huawei Euleros 2_0_sp2 | — | Upgrade file-rollerUpgrade file-roller-nautilus | Feb 22, 2021 | Sep 21, 2019 |
| Huawei Euleros 2_0_sp3 | — | Upgrade file-rollerUpgrade file-roller-nautilus | Apr 30, 2021 | Sep 21, 2019 |
| Huawei Euleros 2_0_sp5 | — | Upgrade file-roller-nautilusUpgrade file-roller | Dec 16, 2020 | Sep 21, 2019 |
| Oracle Solaris | — | Upgrade desktop/archive-manager/file-roller to version 3.24.0-11.4.16.0.1.3.0 on Solaris 11.4 | Dec 18, 2019 | Sep 21, 2019 |
| Oracle_linux | — | Upgrade file-roller | Nov 14, 2020 | Mar 14, 2018 |
| Redhat_linux | — | Upgrade file-roller-debugsourceUpgrade file-rollerNo solution existsUpgrade file-roller-debuginfo | Nov 5, 2020 | Sep 21, 2019 |
| Rocky_linux | — | Upgrade file-roller-debuginfoUpgrade file-rollerUpgrade file-roller-debugsource | Mar 12, 2024 | Sep 21, 2019 |
| Suse | — | Upgrade nautilus-file-rollerUpgrade file-rollerUpgrade file-roller-lang | Apr 24, 2020 | Sep 21, 2019 |
| Ubuntu | — | Upgrade file-roller | Sep 26, 2019 | Sep 21, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub