CVE-2020-11736
Summary
| CVE | CVE-2020-11736 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-04-13 19:15:00 UTC |
| Updated | 2022-04-27 13:20:00 UTC |
| Description | fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location. |
Risk And Classification
Problem Types: CWE-22 | CWE-59
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 20.04 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Operating System | Debian | Debian Linux | 8.0 | All | All | All |
| Application | Gnome | File-roller | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| libarchive: do not follow external links when extracting files (21dfcdbf) · Commits · GNOME / file-roller · GitLab | MISC | gitlab.gnome.org | Patch, Third Party Advisory |
| [SECURITY] [DLA 2180-1] file-roller security update | MLIST | lists.debian.org | Third Party Advisory |
| USN-4332-1: File Roller vulnerability | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| USN-4332-2: File Roller vulnerability | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| GNOME File Roller: Directory traversal (GLSA 202009-06) — Gentoo security | GENTOO | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296059 Oracle Solaris 11.4 Support Repository Update (SRU) 36.0.1.101.2 Missing (CPUJUL2021)
- 296060 Oracle Solaris 11.4 Support Repository Update (SRU) 37.0.1.101.1 Missing (CPUJUL2021)
- 296073 Oracle Solaris 11.4 Support Repository Update (SRU) 24.75.2 Missing (CPUJUL2020)
- 377355 Alibaba Cloud Linux Security Update for file-roller (ALINUX3-SA-2022:0077)
- 670293 EulerOS Security Update for file-roller (EulerOS-SA-2021-1783)
- 940412 AlmaLinux Security Update for file-roller (ALSA-2020:4820)
- 960864 Rocky Linux Security Update for file-roller (RLSA-2020:4820)