CVE-2020-11736 PUBLISHED

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

EPSS 0.34% · 56.2th percentile

Risk Scores

EPSS Score
0.34%
56.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSfile-roller0, 3.28.0-1ubuntu1.1, 3.28.0-1ubuntu1
Ubuntu:20.04:LTSfile-roller3.36.1-1, 3.32.2-1, 3.32.3-1
Ubuntu:16.04:LTSfile-roller3.16.5-0ubuntu1.3, 3.16.5-0ubuntu1.2, 3.16.5-0ubuntu1.1

Timeline

References

Open in Interactive Console →