CVE-2020-36314
Summary
| CVE | CVE-2020-36314 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-04-07 12:15:00 UTC |
| Updated | 2023-11-07 03:22:00 UTC |
| Description | fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| CVE-2020-36314: GNOME Archive Manager Traversal Attack (#108) · Issues · GNOME / File Roller · GitLab |
MISC |
gitlab.gnome.org |
|
| [SECURITY] Fedora 34 Update: file-roller-3.38.0-3.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: file-roller-3.38.0-3.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| libarchive: Skip files with symlinks in parents (e970f496) · Commits · GNOME / File Roller · GitLab |
MISC |
gitlab.gnome.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 198343 Ubuntu Security Notification for File Roller vulnerability (USN-4927-1)
- 239840 Red Hat Update for file-roller (RHSA-2021:4179)
- 281340 Fedora Security Update for file (FEDORA-2021-7109d72f07)
- 296059 Oracle Solaris 11.4 Support Repository Update (SRU) 36.0.1.101.2 Missing (CPUJUL2021)
- 296060 Oracle Solaris 11.4 Support Repository Update (SRU) 37.0.1.101.1 Missing (CPUJUL2021)
- 501549 Alpine Linux Security Update for file-roller
- 671570 EulerOS Security Update for file-roller (EulerOS-SA-2022-1530)
- 671720 EulerOS Security Update for file-roller (EulerOS-SA-2022-1717)
- 940277 AlmaLinux Security Update for file-roller (ALSA-2021:4179)
- 960341 Rocky Linux Security Update for file-roller (RLSA-2021:4179)