CVE-2019-16680
Summary
| CVE | CVE-2019-16680 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-21 21:15:00 UTC |
| Updated | 2019-12-20 17:23:00 UTC |
| Description | An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| updated for version 3.29.91 (e8fb3e24) · Commits · GNOME / file-roller · GitLab |
MISC |
gitlab.gnome.org |
Patch, Third Party Advisory |
| USN-4139-1: File Roller vulnerability | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| 1767594 – (CVE-2019-16680) CVE-2019-16680 file-roller: path traversal vulnerability via a specially crafted filename contained in malicious archive |
MISC |
bugzilla.redhat.com |
Third Party Advisory |
| Bug 794337 – Path traversal vulnerability |
MISC |
bugzilla.gnome.org |
Exploit, Issue Tracking, Vendor Advisory |
| Bugtraq: [SECURITY] [DSA 4537-1] file-roller security update |
BUGTRAQ |
seclists.org |
Mailing List, Third Party Advisory |
| [SECURITY] [DLA 1938-1] file-roller security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| Path traversal vulnerability (57268e51) · Commits · GNOME / file-roller · GitLab |
MISC |
gitlab.gnome.org |
Patch, Third Party Advisory |
| Debian -- Security Information -- DSA-4537-1 file-roller |
DEBIAN |
www.debian.org |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296078 Oracle Solaris 11.4 Support Repository Update (SRU) 16.4.0 Missing (CPUOCT2019)
- 377355 Alibaba Cloud Linux Security Update for file-roller (ALINUX3-SA-2022:0077)
- 670293 EulerOS Security Update for file-roller (EulerOS-SA-2021-1783)
- 940412 AlmaLinux Security Update for file-roller (ALSA-2020:4820)
- 960864 Rocky Linux Security Update for file-roller (RLSA-2020:4820)