CVE-2020-11736: Path Traversal
fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-11736?
CVE-2020-11736 is a vulnerability in GNOME file-roller through version 3.36.1 that allows Directory Traversal during extraction.
What is the severity of CVE-2020-11736?
The severity of CVE-2020-11736 is low, with a CVSS score of 3.9.
How does CVE-2020-11736 affect file-roller?
CVE-2020-11736 affects file-roller versions 3.28.0-1ubuntu1.2, 3.32.2-1ubuntu0.1, 3.36.1-1ubuntu0.1, 3.16.5-0ubuntu1.4, and 3.36.2, as well as other distributions and versions.
Is there a fix for CVE-2020-11736?
Yes, the vulnerability has been patched in file-roller version 3.36.2.
Where can I find more information about CVE-2020-11736?
More information about CVE-2020-11736 can be found at the following references: [CVE-2020-11736](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-11736), [GNOME file-roller commit](https://gitlab.gnome.org/GNOME/file-roller/-/commit/21dfcdbfe258984db89fb65243a1a888924e45a0), [Ubuntu security advisory](https://ubuntu.com/security/notices/USN-4332-1).