QID 198354

Date Published: 2021-05-10

QID 198354: Ubuntu Security Notification for GNOME Autoar vulnerability (USN-4937-1)

Gnome autoar could extract files outside of the intended directory

If a user were tricked into extracting a specially crafted archive, a remote attacker could create files in arbitrary locations, possibly leading to code execution

  • CVSS V3 rated as Medium - 5.5 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Refer to Ubuntu advisory: USN-4937-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198354

    Software Advisories
    Advisory ID Software Component Link
    USN-4937-1 Ubuntu Linux URL Logo usn.ubuntu.com/4937-1