CVE-2020-36314
published 2021-04-07CVE-2020-36314: fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it…
PriorityP413low3.9CVSS 3.1
AVLACLPRLUIRSUCNILAL
EPSS
0.61%
45.2th percentile
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | file-roller | < file-roller 3.38.1-1 (bookworm) | file-roller 3.38.1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| gnome | file-roller | <= 3.38.0 | — |
| gnome | file-roller | >= 0 < 3.38.1-1 | 3.38.1-1 |
| gnome | file-roller | >= 0 < 3.38.1-1 | 3.38.1-1 |
| gnome | file-roller | >= 0 < 3.38.1-1 | 3.38.1-1 |
| gnome | file-roller | >= 0 < 3.38.1-1 | 3.38.1-1 |
CVSS provenance
nvdv3.13.9LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
nvdv2.02.6LOWAV:L/AC:H/Au:N/C:N/I:P/A:P
osv3.9LOW
vendor_debian3.9LOW
vendor_redhat3.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
File Roller vulnerability
vendor_ubuntu·2021-04-26
CVE-2020-36314 File Roller vulnerability
Title: File Roller vulnerability
Summary: File Roller could be made to expose sensitive information.
It was discovered that File Roller incorrectly handled symlinks.
An attacker could possibly use this issue to expose sensitive information.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
file-roller: directory traversal via directory symlink pointing outside of the target directory (incomplete fix for CVE-2020-11736)
vendor_redhat·2021-02-15·CVSS 3.9
CVE-2020-36314 [LOW] CWE-22 file-roller: directory traversal via directory symlink pointing outside of the target directory (incomplete fix for CVE-2020-11736)
file-roller: directory traversal via directory symlink pointing outside of the target directory (incomplete fix for CVE-2020-11736)
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
A path traversal vulnerability was found in file-roller due to an incomplete fix for CVE-2020-11736. It may still be possible to extract files outside of the intended directory in case of malicious archives containing symbolic links. The highest threat from this vulnerability is to data integrity and system availability.
Package: file-roller (Re
Debian
CVE-2020-36314: file-roller - fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Sh...
vendor_debian·2020·CVSS 3.9
CVE-2020-36314 [LOW] CVE-2020-36314: file-roller - fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Sh...
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
Scope: local
bookworm: resolved (fixed in 3.38.1-1)
bullseye: resolved (fixed in 3.38.1-1)
forky: resolved (fixed in 3.38.1-1)
sid: resolved (fixed in 3.38.1-1)
trixie: resolved (fixed in 3.38.1-1)
GHSA
GHSA-xf7f-5p7r-xc3c: fr-archive-libarchive
ghsa_unreviewed·2022-05-24·CVSS 3.9
CVE-2020-36314 [LOW] CWE-22 GHSA-xf7f-5p7r-xc3c: fr-archive-libarchive
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
OSV
CVE-2020-36314: fr-archive-libarchive
osv·2021-04-07·CVSS 3.9
CVE-2020-36314 [LOW] CVE-2020-36314: fr-archive-libarchive
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.gnome.org/GNOME/file-roller/-/commit/e970f4966bf388f6e7c277357c8b186c645683aehttps://gitlab.gnome.org/GNOME/file-roller/-/issues/108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6KJBZVCHQ4SSX2JAJZVJ5J4P3GEMXJ75/https://gitlab.gnome.org/GNOME/file-roller/-/commit/e970f4966bf388f6e7c277357c8b186c645683aehttps://gitlab.gnome.org/GNOME/file-roller/-/issues/108https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6KJBZVCHQ4SSX2JAJZVJ5J4P3GEMXJ75/
2021-04-07
Published