CVE-2020-11736

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
3.9 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
VendorProductVersion
gnomefile-roller
𝑥
≤ 3.36.1
debiandebian_linux
8.0
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
19.10
canonicalubuntu_linux
20.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
file-roller
bullseye
3.38.1-1
fixed
bookworm
43.0-1
fixed
sid
44.3-1
fixed
trixie
44.3-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
file-roller
focal
Fixed 3.36.1-1ubuntu0.1
released
eoan
Fixed 3.32.2-1ubuntu0.1
released
bionic
Fixed 3.28.0-1ubuntu1.2
released
xenial
Fixed 3.16.5-0ubuntu1.4
released
trusty
dne