REDHAT-BUG-1940026: Low severity Gnome gnome-autoar vulnerability
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.
Reference and upstream patch: https://gitlab.gnome.org/GNOME/gnome-autoar/-/commit/8109c368c6cfdb593faaf698c2bf5da32bb1ace4
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1940026?
The severity of REDHAT-BUG-1940026 is classified as critical due to its potential for directory traversal attacks.
How do I fix REDHAT-BUG-1940026?
To fix REDHAT-BUG-1940026, update GNOME gnome-autoar to version 0.3.1 or later.
What software is affected by REDHAT-BUG-1940026?
REDHAT-BUG-1940026 affects GNOME gnome-autoar versions prior to 0.3.1.
What kind of vulnerability is REDHAT-BUG-1940026?
REDHAT-BUG-1940026 is a directory traversal vulnerability that allows unauthorized file access during extraction.
Is there a workaround for REDHAT-BUG-1940026?
There are no specific workarounds recommended for REDHAT-BUG-1940026 other than updating to the fixed version.