REDHAT-BUG-1925640: Low severity Gnome gnome-autoar vulnerability
autoar-extractor.c in GNOME gnome-autoar through 0.2.4, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
Reference: https://gitlab.gnome.org/GNOME/gnome-autoar/-/issues/7
Upstream patch: https://gitlab.gnome.org/GNOME/gnome-autoar/-/commit/adb067e645732fdbe7103516e506d09eb6a54429
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1925640?
The severity of REDHAT-BUG-1925640 is considered critical due to the directory traversal vulnerability.
How do I fix REDHAT-BUG-1925640?
To fix REDHAT-BUG-1925640, update GNOME gnome-autoar to a version later than 0.2.4.
Which software is affected by REDHAT-BUG-1925640?
REDHAT-BUG-1925640 affects GNOME gnome-autoar version 0.2.4 and earlier.
What type of vulnerability is REDHAT-BUG-1925640?
REDHAT-BUG-1925640 is a directory traversal type vulnerability.
Can REDHAT-BUG-1925640 lead to exploitation?
Yes, REDHAT-BUG-1925640 can be exploited to access unauthorized files outside of the intended extraction location.