CVE-2016-7162
published 2016-09-26CVE-2016-7162: The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
3.33%
87.4th percentile
The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | file-roller | < file-roller 3.20.3-1 (bookworm) | file-roller 3.20.3-1 (bookworm) |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| file_roller_project | file_roller | — | — |
| gnome | file-roller | >= 0 < 3.20.3-1 | 3.20.3-1 |
| gnome | file-roller | >= 0 < 3.20.3-1 | 3.20.3-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g3mg-grgw-vqfv: The _g_file_remove_directory function in file-utils
ghsa_unreviewed·2022-05-13
CVE-2016-7162 [HIGH] CWE-20 GHSA-g3mg-grgw-vqfv: The _g_file_remove_directory function in file-utils
The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.
OSV
CVE-2016-7162: The _g_file_remove_directory function in file-utils
osv·2016-09-26·CVSS 7.5
CVE-2016-7162 [HIGH] CVE-2016-7162: The _g_file_remove_directory function in file-utils
The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.
Ubuntu
File Roller vulnerability
vendor_ubuntu·2016-09-08
CVE-2016-7162 File Roller vulnerability
Title: File Roller vulnerability
Summary: File Roller could be made to delete files.
It was discovered that File Roller incorrectly handled symlinks. If a user were
tricked into extracting a specially-crafted archive, an attacker could delete
files outside of the extraction directory.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
file-roller: Path traversal vulnerability when opening crafted archive
vendor_redhat·2016-09-07·CVSS 7.5
CVE-2016-7162 [HIGH] CWE-22 file-roller: Path traversal vulnerability when opening crafted archive
file-roller: Path traversal vulnerability when opening crafted archive
The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.
A path traversal flaw was found in file-roller. If a user were tricked into opening a specially crafted archive and clicking on a symbolic link, file deletion could occur.
Package: file-roller (Red Hat Enterprise Linux 5) - Not affected
Package: file-roller (Red Hat Enterprise Linux 6) - Not affected
Package: file-roller (Red Hat Enterprise Linux 7) - Will not fix
Debian
CVE-2016-7162: file-roller - The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 throu...
vendor_debian·2016·CVSS 7.5
CVE-2016-7162 [HIGH] CVE-2016-7162: file-roller - The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 throu...
The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.
Scope: local
bookworm: resolved (fixed in 3.20.3-1)
bullseye: resolved (fixed in 3.20.3-1)
forky: resolved (fixed in 3.20.3-1)
sid: resolved (fixed in 3.20.3-1)
trixie: resolved (fixed in 3.20.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-7162 file-roller: Path traversal vulnerability when opening crafted archive [fedora-all]
bugzilla·2016-09-08·CVSS 7.5
CVE-2016-7162 [HIGH] CVE-2016-7162 file-roller: Path traversal vulnerability when opening crafted archive [fedora-all]
CVE-2016-7162 file-roller: Path traversal vulnerability when opening crafted archive [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2016-7162 file-roller: Path traversal vulnerability when opening crafted archive
bugzilla·2016-09-08·CVSS 7.5
CVE-2016-7162 [HIGH] CVE-2016-7162 file-roller: Path traversal vulnerability when opening crafted archive
CVE-2016-7162 file-roller: Path traversal vulnerability when opening crafted archive
File Roller 3.5.4 through 3.20.2 was affected by a path traversal bug that could result in deleted files if a user were tricked into opening a malicious archive.
Upstream bug:
https://bugzilla.gnome.org/show_bug.cgi?id=698554
Upstream patch:
https://git.gnome.org/browse/file-roller/commit/?id=f70be1f41688859ec8dbe266df35a1839ceb96c5
CVE assignment:
http://seclists.org/oss-sec/2016/q3/436
Discussion:
Created file-roller tracking bugs for this issue:
Affects: fedora-all [bug 1374276]
---
Since this requires clear user interaction (the link has to be clicked in file roller for deletion to occur), and results at worst in deleted files, security impact is Moderate and likely resolution for rhel is w
http://ftp.gnome.org/mirror/gnome.org/sources/file-roller/3.20/file-roller-3.20.3.newshttp://ftp.gnome.org/mirror/gnome.org/sources/file-roller/3.21/file-roller-3.21.90.newshttp://www.openwall.com/lists/oss-security/2016/09/08/4http://www.securityfocus.com/bid/92896http://www.ubuntu.com/usn/USN-3074-1https://bugzilla.gnome.org/show_bug.cgi?id=698554https://git.gnome.org/browse/file-roller/commit/?id=f70be1f41688859ec8dbe266df35a1839ceb96c5http://ftp.gnome.org/mirror/gnome.org/sources/file-roller/3.20/file-roller-3.20.3.newshttp://ftp.gnome.org/mirror/gnome.org/sources/file-roller/3.21/file-roller-3.21.90.newshttp://www.openwall.com/lists/oss-security/2016/09/08/4http://www.securityfocus.com/bid/92896http://www.ubuntu.com/usn/USN-3074-1https://bugzilla.gnome.org/show_bug.cgi?id=698554https://git.gnome.org/browse/file-roller/commit/?id=f70be1f41688859ec8dbe266df35a1839ceb96c5
2016-09-26
Published