3.9

CVE-2020-11736

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gnome ≫ File-roller Version <= 3.36.1
Debian ≫ Debian Linux Version 8.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition esm
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.77% 0.507
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.9 1.3 2.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
NIST 3.3 3.4 4.9
AV:L/AC:M/Au:N/C:N/I:P/A:P
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://gitlab.gnome.org/GNOME/file-roller/-/commit/21dfcdbfe258984db89fb65243a1a888924e45a0
Patch
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2020/04/msg00013.html
Third Party Advisory
Mailing List
https://security.gentoo.org/glsa/202009-06
Third Party Advisory
https://usn.ubuntu.com/4332-1/
Third Party Advisory
https://usn.ubuntu.com/4332-2/
Third Party Advisory