CVE-2020-36314: Low severity file roller vulnerability
Published Apr 7, 2021
·Updated
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
Affected Software
2 affected components
Gnome file-roller<=3.38.0
Fedoraproject Fedora=34
Remediation
Event History
Apr 7, 2021
CVE Published
via MITRE·11:07 AM
Data Sourced
via MITRE·11:07 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-36314.
2
What is the affected software?
The affected software is GNOME file-roller through version 3.38.0 and Fedora 34.
3
What is the severity of CVE-2020-36314?
The severity of CVE-2020-36314 is low, with a severity value of 3.9.
4
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-59.
5
How can I fix the vulnerability?
To fix the vulnerability, update GNOME file-roller to a version higher than 3.38.0 and Fedora to a version higher than 34.