GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Mon Sep 14, 2020 2:26 am Post subject: [ GLSA 202009-06 ] GNOME File Roller |
|
|
Gentoo Linux Security Advisory
Title: GNOME File Roller: Directory traversal (GLSA 202009-06)
Severity: normal
Exploitable: local, remote
Date: 2020-09-13
Bug(s): #717362
ID: 202009-06
Synopsis
A vulnerability in GNOME File Roller could lead to a directory
traversal attack.
Background
File Roller is an archive manager for the GNOME desktop environment.
Affected Packages
Package: app-arch/file-roller
Vulnerable: < 3.36.3
Unaffected: >= 3.36.3
Architectures: All supported architectures
Description
It was discovered that GNOME File Roller incorrectly handled symlinks.
Impact
Please review the referenced CVE identifiers for details.
Workaround
There is no known workaround at this time.
Resolution
All GNOME File Roller users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-arch/file-roller-3.36.3"
|
References
CVE-2020-11736 |
|