File Roller GNOME File Roller

Do you want an email whenever new security vulnerabilities are reported in GNOME File Roller?

By the Year

In 2024 there have been 0 vulnerabilities in GNOME File Roller . File Roller did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 1 3.90
2020 1 3.90
2019 1 4.30
2018 0 0.00

It may take a day or so for new File Roller vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent GNOME File Roller Security Vulnerabilities

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software

CVE-2020-36314 3.9 - Low - April 07, 2021

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

Directory traversal

fr-archive-libarchive.c in GNOME file-roller through 3.36.1

CVE-2020-11736 3.9 - Low - April 13, 2020

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

Directory traversal

An issue was discovered in GNOME file-roller before 3.29.91

CVE-2019-16680 4.3 - Medium - September 21, 2019

An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.

Directory traversal

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Red Hat Enterprise Linux (RHEL) or by GNOME? Click the Watch button to subscribe.

GNOME
Vendor

subscribe