CVE-2020-36314 - log back

CVE-2020-36314 edited at 07 Apr 2021 12:09:33
References
https://gitlab.gnome.org/GNOME/file-roller/-/issues/108
- https://gitlab.gnome.org/GNOME/file-roller/-/commit/e970f4966bf388f6e7c277357c8b186c645683ae
+ https://gitlab.gnome.org/GNOME/file-roller/-/commit/0bd4a14f3bc8dae7c68469f281da9fddbe9e0d02
CVE-2020-36314 edited at 07 Apr 2021 12:04:58
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Directory traversal
Description
+ fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
References
+ https://gitlab.gnome.org/GNOME/file-roller/-/issues/108
+ https://gitlab.gnome.org/GNOME/file-roller/-/commit/e970f4966bf388f6e7c277357c8b186c645683ae
Notes
CVE-2020-36314 created at 07 Apr 2021 12:03:57