7.5
CVSSv3

CVE-2016-7162

Published: 26/09/2016 Updated: 14/04/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 up to and including 3.20.2 allows remote malicious users to delete arbitrary files via a symlink attack on a folder in an archive.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

file roller project file roller 3.5.4

file roller project file roller 3.6.0

file roller project file roller 3.6.1

file roller project file roller 3.6.1.1

file roller project file roller 3.6.2

file roller project file roller 3.6.3

file roller project file roller 3.6.4

file roller project file roller 3.8.0

file roller project file roller 3.8.1

file roller project file roller 3.8.2

file roller project file roller 3.8.3

file roller project file roller 3.9.0

file roller project file roller 3.9.1

file roller project file roller 3.9.2

file roller project file roller 3.9.3

file roller project file roller 3.10

file roller project file roller 3.15

file roller project file roller 3.20

file roller project file roller 3.20.1

file roller project file roller 3.20.2

Vendor Advisories

File Roller could be made to delete files ...
A path traversal flaw was found in file-roller If a user were tricked into opening a specially crafted archive and clicking on a symbolic link, file deletion could occur ...