CVE-2020-11736

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.9 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 56%
Affected Products (NVD)
VendorProductVersion
gnomefile-roller
𝑥
≤ 3.36.1
debiandebian_linux
8.0
canonicalubuntu_linux
16.04
canonicalubuntu_linux
18.04
canonicalubuntu_linux
19.10
canonicalubuntu_linux
20.04
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
file-roller
bookworm
43.0-1
fixed
bullseye
3.38.1-1
fixed
sid
44.3-1
fixed
trixie
44.3-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
file-roller
bionic
Fixed 3.28.0-1ubuntu1.2
released
eoan
Fixed 3.32.2-1ubuntu0.1
released
focal
Fixed 3.36.1-1ubuntu0.1
released
trusty
dne
xenial
Fixed 3.16.5-0ubuntu1.4
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
file-roller
suse enterprise desktop 15 SP1
3.26.2-4.5.1
fixed
suse enterprise desktop 15 SP2
3.32.5-1.8
fixed
suse enterprise desktop 15 SP3
3.32.5-1.8
fixed
suse enterprise desktop 15 SP4
3.40.0-150400.3.13
fixed
suse enterprise desktop 15 SP5
3.40.0-150400.3.13
fixed
suse enterprise desktop 15 SP6
43.1-150600.1.3
fixed
suse enterprise desktop 15 SP7
43.1-150600.1.3
fixed
suse enterprise sap 12 SP4
3.20.3-15.6.1
fixed
suse enterprise sap 12 SP5
3.20.3-15.6.1
fixed
suse enterprise sap 15 SP1
3.26.2-4.5.1
fixed
suse enterprise sap 15 SP2
3.32.5-1.8
fixed
suse enterprise sap 15 SP3
3.32.5-1.8
fixed
suse enterprise sap 15 SP4
3.40.0-150400.3.13
fixed
suse enterprise sap 15 SP5
3.40.0-150400.3.13
fixed
suse enterprise sap 15 SP6
43.1-150600.1.3
fixed
suse enterprise sap 15 SP7
43.1-150600.1.3
fixed
suse enterprise server 12 SP3
3.20.3-15.6.1
fixed
suse enterprise server 12 SP4
3.20.3-15.6.1
fixed
suse enterprise server 12 SP5
3.20.3-15.6.1
fixed
suse enterprise server 15 SP1
3.26.2-4.5.1
fixed
suse enterprise server 15 SP2
3.32.5-1.8
fixed
suse enterprise server 15 SP3
3.32.5-1.8
fixed
suse enterprise server 15 SP4
3.40.0-150400.3.13
fixed
suse enterprise server 15 SP5
3.40.0-150400.3.13
fixed
suse enterprise server 15 SP6
43.1-150600.1.3
fixed
suse enterprise server 15 SP7
43.1-150600.1.3
fixed
file-roller-lang
suse enterprise desktop 15 SP1
3.26.2-4.5.1
fixed
suse enterprise desktop 15 SP2
3.32.5-1.8
fixed
suse enterprise desktop 15 SP3
3.32.5-1.8
fixed
suse enterprise desktop 15 SP4
3.40.0-150400.3.13
fixed
suse enterprise desktop 15 SP5
3.40.0-150400.3.13
fixed
suse enterprise desktop 15 SP6
43.1-150600.1.3
fixed
suse enterprise desktop 15 SP7
43.1-150600.1.3
fixed
suse enterprise sap 12 SP4
3.20.3-15.6.1
fixed
suse enterprise sap 12 SP5
3.20.3-15.6.1
fixed
suse enterprise sap 15 SP1
3.26.2-4.5.1
fixed
suse enterprise sap 15 SP2
3.32.5-1.8
fixed
suse enterprise sap 15 SP3
3.32.5-1.8
fixed
suse enterprise sap 15 SP4
3.40.0-150400.3.13
fixed
suse enterprise sap 15 SP5
3.40.0-150400.3.13
fixed
suse enterprise sap 15 SP6
43.1-150600.1.3
fixed
suse enterprise sap 15 SP7
43.1-150600.1.3
fixed
suse enterprise server 12 SP3
3.20.3-15.6.1
fixed
suse enterprise server 12 SP4
3.20.3-15.6.1
fixed
suse enterprise server 12 SP5
3.20.3-15.6.1
fixed
suse enterprise server 15 SP1
3.26.2-4.5.1
fixed
suse enterprise server 15 SP2
3.32.5-1.8
fixed
suse enterprise server 15 SP3
3.32.5-1.8
fixed
suse enterprise server 15 SP4
3.40.0-150400.3.13
fixed
suse enterprise server 15 SP5
3.40.0-150400.3.13
fixed
suse enterprise server 15 SP6
43.1-150600.1.3
fixed
suse enterprise server 15 SP7
43.1-150600.1.3
fixed
nautilus-file-roller
suse enterprise sap 12 SP4
3.20.3-15.6.1
fixed
suse enterprise sap 12 SP5
3.20.3-15.6.1
fixed
suse enterprise server 12 SP3
3.20.3-15.6.1
fixed
suse enterprise server 12 SP4
3.20.3-15.6.1
fixed
suse enterprise server 12 SP5
3.20.3-15.6.1
fixed