Back

MEDIUM

file-roller: path sanitization errors

Published Jul 18, 2013

Description

Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote attackers to create arbitrary files via a crafted archive that is not properly handled in a "Keep directory structure" action, related to fr-archive-libarchive.c and fr-window.c.

Affected products

Remediation

Red Hat statement

Not Vulnerable. This issue does not affect the version of file-roller as shipped with Red Hat Enterprise Linux 5 and 6.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 18, 2013
Updated Aug 6, 2024
Reserved Jun 24, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Jul 8, 2013