CVE-2016-7162: Input Validation
Published Sep 26, 2016
·Updated
The gfileremovedirectory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.
Affected Software
22 affected components
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
File Roller Project File Roller Gnome=3.5.4
File Roller Project File Roller Gnome=3.6.0
File Roller Project File Roller Gnome=3.6.1
File Roller Project File Roller Gnome=3.6.1.1
File Roller Project File Roller Gnome=3.6.2
File Roller Project File Roller Gnome=3.6.3
File Roller Project File Roller Gnome=3.6.4
File Roller Project File Roller Gnome=3.8.0
File Roller Project File Roller Gnome=3.8.1
File Roller Project File Roller Gnome=3.8.2
File Roller Project File Roller Gnome=3.8.3
File Roller Project File Roller Gnome=3.9.0
File Roller Project File Roller Gnome=3.9.1
File Roller Project File Roller Gnome=3.9.2
File Roller Project File Roller Gnome=3.9.3
File Roller Project File Roller Gnome=3.10
File Roller Project File Roller Gnome=3.15
File Roller Project File Roller Gnome=3.20
File Roller Project File Roller Gnome=3.20.1
File Roller Project File Roller Gnome=3.20.2
Remediation
Event History
Sep 26, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-7162?
CVE-2016-7162 is classified as a medium severity vulnerability due to the risk of arbitrary file deletion through symlink attacks.
2
How do I fix CVE-2016-7162?
To fix CVE-2016-7162, upgrade File Roller to version 3.20.3 or later.
3
What impact does CVE-2016-7162 have on Ubuntu Linux?
CVE-2016-7162 allows remote attackers to delete arbitrary files on systems running vulnerable versions of File Roller in Ubuntu Linux.
4
Which versions of File Roller are affected by CVE-2016-7162?
CVE-2016-7162 affects File Roller versions from 3.5.4 up to and including 3.20.2.
5
Can CVE-2016-7162 be exploited remotely?
Yes, CVE-2016-7162 can be exploited remotely via symlink attacks on folders in archives.