fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
CVSS Details
- CVSS 3.1 Base Score: 3.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade file-roller | May 4, 2022 | Apr 7, 2021 |
| Alpine Linux | — | Upgrade file-roller | Oct 1, 2024 | Apr 7, 2021 |
| Centos_linux | — | Upgrade file-roller-debugsourceUpgrade file-roller-debuginfoUpgrade file-roller | Nov 10, 2021 | Apr 7, 2021 |
| Debian | — | Upgrade file-roller | Jul 30, 2024 | Apr 7, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade file-rollerUpgrade file-roller-nautilus | May 25, 2022 | Apr 7, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade file-roller-nautilusUpgrade file-roller | Apr 26, 2022 | Apr 7, 2021 |
| Oracle Solaris | — | Upgrade desktop/archive-manager/file-roller to version 3.38.1-11.4.36.0.1.101.0 on Solaris 11.4 | Aug 27, 2021 | Apr 7, 2021 |
| Redhat_linux | — | Upgrade file-roller-debugsourceNo solution existsUpgrade file-roller-debuginfoUpgrade file-roller | Nov 10, 2021 | Apr 7, 2021 |
| Rocky_linux | — | Upgrade file-roller-debuginfoUpgrade file-roller-debugsourceUpgrade file-roller | Mar 12, 2024 | Apr 7, 2021 |
| Suse | — | Upgrade file-rollerUpgrade file-roller-lang | Aug 9, 2024 | Apr 7, 2021 |
| Ubuntu | — | Upgrade file-roller | Apr 27, 2021 | Apr 7, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub