First published: Wed Apr 07 2021(Updated: )
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNOME file-roller | <=3.38.0 | |
Fedoraproject Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-36314.
The affected software is GNOME file-roller through version 3.38.0 and Fedora 34.
The severity of CVE-2020-36314 is low, with a severity value of 3.9.
The CWE ID for this vulnerability is CWE-59.
To fix the vulnerability, update GNOME file-roller to a version higher than 3.38.0 and Fedora to a version higher than 34.