cbcvebase.
CVE-2013-4668
published 2013-07-18

CVE-2013-4668: Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote…

PriorityP434medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
4.31%
90.2th percentile
Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote attackers to create arbitrary files via a crafted archive that is not properly handled in a "Keep directory structure" action, related to fr-archive-libarchive.c and fr-window.c.

Affected

10 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianfile-roller< file-roller 3.8.3-1 (bookworm)file-roller 3.8.3-1 (bookworm)
file_roller_projectfile_roller>= 3.6.0 < 3.6.43.6.4
file_roller_projectfile_roller>= 3.8.0 < 3.8.33.8.3
file_roller_projectfile_roller>= 3.9.1 < 3.9.33.9.3
gnomefile-roller>= 0 < 3.8.3-13.8.3-1
gnomefile-roller>= 0 < 3.8.3-13.8.3-1
gnomefile-roller>= 0 < 3.8.3-13.8.3-1
gnomefile-roller>= 0 < 3.8.3-13.8.3-1

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.