USN-4332-1: File Roller vulnerability
Published Apr 20, 2020
·Updated
It was discovered that File Roller incorrectly handled symlinks. An attacker could possibly use this issue to expose sensitive information.
Affected Software
6 affected componentsFixes available
All of the following
ubuntu/file-roller<3.32.2-1ubuntu0.1
3.32.2-1ubuntu0.1
Ubuntu Ubuntu=19.10
All of the following
ubuntu/file-roller<3.28.0-1ubuntu1.2
3.28.0-1ubuntu1.2
Ubuntu Ubuntu=18.04
All of the following
ubuntu/file-roller<3.16.5-0ubuntu1.4
3.16.5-0ubuntu1.4
Ubuntu Ubuntu=16.04
Event History
Apr 20, 2020
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is USN-4332-1.
2
What software is affected by this vulnerability?
The File Roller software is affected by this vulnerability.
3
What is the severity of this vulnerability?
The severity of this vulnerability is not specified in the information provided.
4
How can an attacker exploit this vulnerability?
An attacker could exploit this vulnerability by using File Roller incorrectly handling symlinks to expose sensitive information.
5
How can I fix this vulnerability?
To fix this vulnerability, update the File Roller software to version 3.32.2-1ubuntu0.1 or later.