LWN.net Logo

Advertisement

GStreamer, Embedded Linux, Android, VoD, Smooth Streaming, DRM, RTSP, HEVC, PulseAudio, OpenGL. Register now to attend.

Advertise here

file-roller: path traversal

Package(s):file-roller CVE #(s):CVE-2013-4668
Created:July 16, 2013 Updated:July 31, 2013
Description: From the Fedora advisory:

The File Roller archive manager for the GNOME desktop suffers from a path traversal vulnerability caused by insufficient path sanitization.

A specially crafted archive file can be used to trigger creation of arbitrary files in any location, writable by the user executing the extraction, outside the current working directory. This behaviour is triggered when the option 'Keep directory structure' is selected from the application 'Extract' dialog.

Alerts:
Fedora FEDORA-2013-12667 2013-07-16
Ubuntu USN-1906-1 2013-07-16
Fedora FEDORA-2013-12653 2013-07-24
openSUSE openSUSE-SU-2013:1281-1 2013-07-31

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds