VDB
GCVE-VVD-MAGEIA-2021-311
GCVE-VVD-MAGEIA-2021-311
Advisory Published
Updated file-roller package fixes security vulnerability:
A path traversal vulnerability was found in file-roller due to an
incomplete fix for CVE-2020-11736. It may still be possible to extract
files outside of the intended directory in case of malicious archives
containing symbolic links. The highest threat from this vulnerability
is to data integrity and system availability (CVE-2020-36314).
Also, the patch for CVE-2020-11736 was not applied correctly in the
previous update for Mageia 7 (MGASA-2020-0218). This has been corrected.
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | file-roller | 0 (affected), 3.38.0-1.1.mga8 (unaffected) | — |
| Mageia | file-roller | 0 (affected), 3.32.1-2.2.mga7 (unaffected) | — |
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.