fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
2021-04-07T12:15:12.733
2024-11-21T05:29:15.130
Modified
CVSSv3.1: 3.9 (LOW)
AV:L/AC:H/Au:N/C:N/I:P/A:P
1.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gnome | file-roller | ≤ 3.38.0 | Yes |
Operating System | fedoraproject | fedora | 34 | Yes |