CVE-2020-11736
published 2020-04-13CVE-2020-11736: fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is…
PriorityP415low3.9CVSS 3.1
AVLACLPRLUIRSUCNILAL
EPSS
0.77%
51.4th percentile
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | file-roller | < file-roller 3.38.1-1 (bookworm) | file-roller 3.38.1-1 (bookworm) |
| debian | file-roller | < file-roller 3.36.2-1 (bookworm) | file-roller 3.36.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| gnome | file-roller | <= 3.38.0 | — |
| gnome | file-roller | <= 3.36.1 | — |
| gnome | file-roller | >= 0 < 3.36.2-1 | 3.36.2-1 |
| gnome | file-roller | >= 0 < 3.38.1-1 | 3.38.1-1 |
| gnome | file-roller | >= 0 < 3.36.2-1 | 3.36.2-1 |
| gnome | file-roller | >= 0 < 3.38.1-1 | 3.38.1-1 |
| gnome | file-roller | >= 0 < 3.36.2-1 | 3.36.2-1 |
| gnome | file-roller | >= 0 < 3.38.1-1 | 3.38.1-1 |
| gnome | file-roller | >= 0 < 3.36.2-1 | 3.36.2-1 |
| gnome | file-roller | >= 0 < 3.38.1-1 | 3.38.1-1 |
CVSS provenance
nvdv3.13.9LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:N/I:P/A:P
osv3.9LOW
vendor_debian3.9LOW
vendor_redhat3.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
file-roller: directory traversal via directory symlink pointing outside of the target directory (incomplete fix for CVE-2020-11736)
vendor_redhat·2021-02-15·CVSS 3.9
CVE-2020-36314 [LOW] CWE-22 file-roller: directory traversal via directory symlink pointing outside of the target directory (incomplete fix for CVE-2020-11736)
file-roller: directory traversal via directory symlink pointing outside of the target directory (incomplete fix for CVE-2020-11736)
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
A path traversal vulnerability was found in file-roller due to an incomplete fix for CVE-2020-11736. It may still be possible to extract files outside of the intended directory in case of malicious archives containing symbolic links. The highest threat from this vulnerability is to data integrity and system availability.
Package: file-roller (Re
Ubuntu
File Roller vulnerability
vendor_ubuntu·2020-04-27
CVE-2020-11736 File Roller vulnerability
Title: File Roller vulnerability
Summary: File Roller could be made to expose sensitive information.
USN-4332-1 fixed vulnerabilities in File Roller. This update provides
the corresponding update for Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that File Roller incorrectly handled symlinks.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
File Roller vulnerability
vendor_ubuntu·2020-04-20
CVE-2020-11736 File Roller vulnerability
Title: File Roller vulnerability
Summary: File Roller could be made to expose sensitive information.
It was discovered that File Roller incorrectly handled symlinks.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
file-roller: directory traversal via directory symlink pointing outside of the target directory
vendor_redhat·2020-04-12·CVSS 3.9
CVE-2020-11736 [LOW] CWE-22 file-roller: directory traversal via directory symlink pointing outside of the target directory
file-roller: directory traversal via directory symlink pointing outside of the target directory
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
Package: file-roller (Red Hat Enterprise Linux 5) - Out of support scope
Package: file-roller (Red Hat Enterprise Linux 6) - Out of support scope
Package: file-roller (Red Hat Enterprise Linux 7) - Fix deferred
Debian
CVE-2020-36314: file-roller - fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Sh...
vendor_debian·2020·CVSS 3.9
CVE-2020-36314 [LOW] CVE-2020-36314: file-roller - fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Sh...
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
Scope: local
bookworm: resolved (fixed in 3.38.1-1)
bullseye: resolved (fixed in 3.38.1-1)
forky: resolved (fixed in 3.38.1-1)
sid: resolved (fixed in 3.38.1-1)
trixie: resolved (fixed in 3.38.1-1)
Debian
CVE-2020-11736: file-roller - fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Tra...
vendor_debian·2020·CVSS 3.9
CVE-2020-11736 [LOW] CVE-2020-11736: file-roller - fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Tra...
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
Scope: local
bookworm: resolved (fixed in 3.36.2-1)
bullseye: resolved (fixed in 3.36.2-1)
forky: resolved (fixed in 3.36.2-1)
sid: resolved (fixed in 3.36.2-1)
trixie: resolved (fixed in 3.36.2-1)
GHSA
GHSA-jj2q-v22w-qp64: fr-archive-libarchive
ghsa_unreviewed·2022-05-24
CVE-2020-11736 [LOW] CWE-22 GHSA-jj2q-v22w-qp64: fr-archive-libarchive
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
GHSA
GHSA-xf7f-5p7r-xc3c: fr-archive-libarchive
ghsa_unreviewed·2022-05-24·CVSS 3.9
CVE-2020-36314 [LOW] CWE-22 GHSA-xf7f-5p7r-xc3c: fr-archive-libarchive
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
OSV
CVE-2020-36314: fr-archive-libarchive
osv·2021-04-07·CVSS 3.9
CVE-2020-36314 [LOW] CVE-2020-36314: fr-archive-libarchive
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
OSV
CVE-2020-11736: fr-archive-libarchive
osv·2020-04-13·CVSS 3.9
CVE-2020-11736 [LOW] CVE-2020-11736: fr-archive-libarchive
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-11736 file-roller: directory traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location [fedora-al
bugzilla·2020-04-16·CVSS 3.9
CVE-2020-11736 [LOW] CVE-2020-11736 file-roller: directory traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location [fedora-al
CVE-2020-11736 file-roller: directory traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the
Bugzilla
CVE-2020-11736 file-roller: directory traversal via directory symlink pointing outside of the target directory
bugzilla·2020-04-16·CVSS 3.9
CVE-2020-11736 [LOW] CVE-2020-11736 file-roller: directory traversal via directory symlink pointing outside of the target directory
CVE-2020-11736 file-roller: directory traversal via directory symlink pointing outside of the target directory
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
Reference and upstream commit:
https://gitlab.gnome.org/GNOME/file-roller/-/commit/21dfcdbfe258984db89fb65243a1a888924e45a0
Discussion:
Created file-roller tracking bugs for this issue:
Affects: fedora-all [bug 1824990]
---
Created file-roller tracking bugs for this issue:
Affects: fedora-all [bug 1824990]
---
There's an issue with file-roller, during archive extraction the function extract_archive_thread() doesn't check whether a existing symli
https://gitlab.gnome.org/GNOME/file-roller/-/commit/21dfcdbfe258984db89fb65243a1a888924e45a0https://lists.debian.org/debian-lts-announce/2020/04/msg00013.htmlhttps://security.gentoo.org/glsa/202009-06https://usn.ubuntu.com/4332-1/https://usn.ubuntu.com/4332-2/https://gitlab.gnome.org/GNOME/file-roller/-/commit/21dfcdbfe258984db89fb65243a1a888924e45a0https://lists.debian.org/debian-lts-announce/2020/04/msg00013.htmlhttps://security.gentoo.org/glsa/202009-06https://usn.ubuntu.com/4332-1/https://usn.ubuntu.com/4332-2/
2020-04-13
Published