3.9
CVSSv3

CVE-2020-36314

Published: 07/04/2021 Updated: 07/11/2023
CVSS v2 Base Score: 2.6 | Impact Score: 4.9 | Exploitability Score: 1.9
CVSS v3 Base Score: 3.9 | Impact Score: 2.5 | Exploitability Score: 1.3
VMScore: 231
Vector: AV:L/AC:H/Au:N/C:N/I:P/A:P

Vulnerability Summary

fr-archive-libarchive.c in GNOME file-roller up to and including 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

gnome file-roller

fedoraproject fedora 34

Vendor Advisories

fr-archive-libarchivec in GNOME file-roller through 3380, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations NOTE: this issue exists because of an incomplete fix for CVE-2020-11736 ...