CVE-2020-36241
published 2021-02-05CVE-2020-36241: autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction…
PriorityP426medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.64%
46.5th percentile
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnome-autoar | < gnome-autoar 0.4.0-1 (bookworm) | gnome-autoar 0.4.0-1 (bookworm) |
| debian | gnome-autoar | < gnome-autoar 0.2.4-3 (bookworm) | gnome-autoar 0.2.4-3 (bookworm) |
| fedoraproject | fedora | — | — |
| gnome | gnome-autoar | < 0.3.1 | 0.3.1 |
| gnome | gnome-autoar | <= 0.2.4 | — |
| gnome | gnome-autoar | >= 0 < 0.2.4-3 | 0.2.4-3 |
| gnome | gnome-autoar | >= 0 < 0.2.4-3 | 0.2.4-3 |
| gnome | gnome-autoar | >= 0 < 0.4.0-1 | 0.4.0-1 |
| gnome | gnome-autoar | >= 0 < 0.2.4-3 | 0.2.4-3 |
| gnome | gnome-autoar | >= 0 < 0.4.0-1 | 0.4.0-1 |
| gnome | gnome-autoar | >= 0 < 0.2.4-3 | 0.2.4-3 |
| gnome | gnome-autoar | >= 0 < 0.4.0-1 | 0.4.0-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GNOME gnome-autoar up to 0.2.4 Extraction autoar-extractor.c pathname traversal (Nessus ID 316149)
vuldb·2026-05-24·CVSS 5.5
CVE-2020-36241 [MEDIUM] GNOME gnome-autoar up to 0.2.4 Extraction autoar-extractor.c pathname traversal (Nessus ID 316149)
A vulnerability has been found in GNOME gnome-autoar up to 0.2.4 and classified as critical. This issue affects some unknown processing of the file autoar-extractor.c of the component Extraction Handler. Performing a manipulation results in pathname traversal.
This vulnerability is known as CVE-2020-36241. Access to the local network is required for this attack. No exploit is available.
It is suggested to install a patch to address this issue.
GHSA
GHSA-7ppq-qp29-rvgj: autoar-extractor
ghsa_unreviewed·2022-05-24·CVSS 5.5
CVE-2021-28650 [MEDIUM] CWE-59 GHSA-7ppq-qp29-rvgj: autoar-extractor
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.
GHSA
GHSA-vm56-hj47-795x: autoar-extractor
ghsa_unreviewed·2022-05-24
CVE-2020-36241 [MEDIUM] CWE-22 GHSA-vm56-hj47-795x: autoar-extractor
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
OSV
CVE-2021-28650: autoar-extractor
osv·2021-03-17·CVSS 5.5
CVE-2021-28650 [MEDIUM] CVE-2021-28650: autoar-extractor
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.
OSV
CVE-2020-36241: autoar-extractor
osv·2021-02-05·CVSS 5.5
CVE-2020-36241 [MEDIUM] CVE-2020-36241: autoar-extractor
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
Red Hat
gnome-autoar: Directory traversal via directory symbolic links pointing outside of the destination directory (incomplete CVE-2020-36241 fix)
vendor_redhat·2021-03-01·CVSS 5.5
CVE-2021-28650 [MEDIUM] CWE-22 gnome-autoar: Directory traversal via directory symbolic links pointing outside of the destination directory (incomplete CVE-2020-36241 fix)
gnome-autoar: Directory traversal via directory symbolic links pointing outside of the destination directory (incomplete CVE-2020-36241 fix)
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.
Package: gnome-autoar (Red Hat Enterprise Linux 9) - Not affected
Ubuntu
GNOME Autoar vulnerability
vendor_ubuntu·2021-02-11
CVE-2020-36241 GNOME Autoar vulnerability
Title: GNOME Autoar vulnerability
Summary: GNOME Autoar could be made to overwrite files.
Yiğit Can Yılmaz discovered that GNOME Autoar could extract files outside
of the intended directory. If a user were tricked into extracting a
specially crafted archive, a remote attacker could create files in
arbitrary locations, possibly leading to code execution.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Debian
CVE-2021-28650: gnome-autoar - autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, N...
vendor_debian·2021·CVSS 5.5
CVE-2021-28650 [MEDIUM] CVE-2021-28650: gnome-autoar - autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, N...
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.
Scope: local
bookworm: resolved (fixed in 0.4.0-1)
bullseye: open
forky: resolved (fixed in 0.4.0-1)
sid: resolved (fixed in 0.4.0-1)
trixie: resolved (fixed in 0.4.0-1)
Red Hat
gnome-autoar: Directory traversal via directory symbolic links pointing outside of the destination directory
vendor_redhat·2020-11-06·CVSS 5.5
CVE-2020-36241 [MEDIUM] CWE-22 gnome-autoar: Directory traversal via directory symbolic links pointing outside of the destination directory
gnome-autoar: Directory traversal via directory symbolic links pointing outside of the destination directory
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
Package: gnome-autoar (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2020-36241: gnome-autoar - autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, ...
vendor_debian·2020·CVSS 5.5
CVE-2020-36241 [MEDIUM] CVE-2020-36241: gnome-autoar - autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, ...
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
Scope: local
bookworm: resolved (fixed in 0.2.4-3)
bullseye: resolved (fixed in 0.2.4-3)
forky: resolved (fixed in 0.2.4-3)
sid: resolved (fixed in 0.2.4-3)
trixie: resolved (fixed in 0.2.4-3)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.gnome.org/GNOME/gnome-autoar/-/commit/adb067e645732fdbe7103516e506d09eb6a54429https://gitlab.gnome.org/GNOME/gnome-autoar/-/issues/7https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BN5TVQ7OHZEGY6AGFLAZWCVCI53RYNHQ/https://security.gentoo.org/glsa/202105-10https://gitlab.gnome.org/GNOME/gnome-autoar/-/commit/adb067e645732fdbe7103516e506d09eb6a54429https://gitlab.gnome.org/GNOME/gnome-autoar/-/issues/7https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BN5TVQ7OHZEGY6AGFLAZWCVCI53RYNHQ/https://security.gentoo.org/glsa/202105-10
2021-02-05
Published