CVE-2021-28650
published 2021-03-17CVE-2021-28650: autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction…
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.53%
41.8th percentile
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gnome-autoar | < gnome-autoar 0.4.0-1 (bookworm) | gnome-autoar 0.4.0-1 (bookworm) |
| fedoraproject | fedora | — | — |
| gnome | gnome-autoar | < 0.3.1 | 0.3.1 |
| gnome | gnome-autoar | >= 0 < 0.4.0-1 | 0.4.0-1 |
| gnome | gnome-autoar | >= 0 < 0.4.0-1 | 0.4.0-1 |
| gnome | gnome-autoar | >= 0 < 0.4.0-1 | 0.4.0-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7ppq-qp29-rvgj: autoar-extractor
ghsa_unreviewed·2022-05-24·CVSS 5.5
CVE-2021-28650 [MEDIUM] CWE-59 GHSA-7ppq-qp29-rvgj: autoar-extractor
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.
OSV
CVE-2021-28650: autoar-extractor
osv·2021-03-17·CVSS 5.5
CVE-2021-28650 [MEDIUM] CVE-2021-28650: autoar-extractor
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.
Ubuntu
GNOME Autoar vulnerability
vendor_ubuntu·2021-05-06
CVE-2021-28650 GNOME Autoar vulnerability
Title: GNOME Autoar vulnerability
Summary: GNOME Autoar could be made to overwrite files.
Ondrej Holy discovered that GNOME Autoar could extract files outside of the
intended directory. If a user were tricked into extracting a specially
crafted archive, a remote attacker could create files in arbitrary
locations, possibly leading to code execution.
Instructions: After a standard system update you need to restart your session to make all
the necessary changes.
Red Hat
gnome-autoar: Directory traversal via directory symbolic links pointing outside of the destination directory (incomplete CVE-2020-36241 fix)
vendor_redhat·2021-03-01·CVSS 5.5
CVE-2021-28650 [MEDIUM] CWE-22 gnome-autoar: Directory traversal via directory symbolic links pointing outside of the destination directory (incomplete CVE-2020-36241 fix)
gnome-autoar: Directory traversal via directory symbolic links pointing outside of the destination directory (incomplete CVE-2020-36241 fix)
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.
Package: gnome-autoar (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2021-28650: gnome-autoar - autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, N...
vendor_debian·2021·CVSS 5.5
CVE-2021-28650 [MEDIUM] CVE-2021-28650: gnome-autoar - autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, N...
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.
Scope: local
bookworm: resolved (fixed in 0.4.0-1)
bullseye: open
forky: resolved (fixed in 0.4.0-1)
sid: resolved (fixed in 0.4.0-1)
trixie: resolved (fixed in 0.4.0-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://gitlab.gnome.org/GNOME/gnome-autoar/-/commit/8109c368c6cfdb593faaf698c2bf5da32bb1ace4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BN5TVQ7OHZEGY6AGFLAZWCVCI53RYNHQ/https://security.gentoo.org/glsa/202105-10https://gitlab.gnome.org/GNOME/gnome-autoar/-/commit/8109c368c6cfdb593faaf698c2bf5da32bb1ace4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BN5TVQ7OHZEGY6AGFLAZWCVCI53RYNHQ/https://security.gentoo.org/glsa/202105-10
2021-03-17
Published