|
|
Subscribe / Log in / New account

Fedora alert FEDORA-2013-12653 (file-roller)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 18 Update: file-roller-3.6.4-1.fc18
Date:  Wed, 24 Jul 2013 03:42:20 +0000
Message-ID:  <20130724034219.EB86821B95@bastion01.phx2.fedoraproject.org>
Archive‑link:  Article

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2013-12653 2013-07-09 23:56:18 -------------------------------------------------------------------------------- Name : file-roller Product : Fedora 18 Version : 3.6.4 Release : 1.fc18 URL : http://download.gnome.org/sources/file-roller/ Summary : Tool for viewing and creating archives Description : File Roller is an application for creating and viewing archives files, such as tar or zip files. -------------------------------------------------------------------------------- Update Information: This update fixes CVE-2013-4668: The File Roller archive manager for the GNOME desktop suffers from a path traversal vulnerability caused by insufficient path sanitization. A specially crafted archive file can be used to trigger creation of arbitrary files in any location, writable by the user executing the extraction, outside the current working directory. This behaviour is triggered when the option 'Keep directory structure' is selected from the application 'Extract' dialog. -------------------------------------------------------------------------------- ChangeLog: * Mon Jul 8 2013 Matthias Clasen <mclasen@redhat.com> - 3.6.4-1 - Update to 3.6.4 * Thu Jan 17 2013 Tomas Bzatek <tbzatek@redhat.com> - 3.6.3-2 - Rebuilt for new libarchive -------------------------------------------------------------------------------- References: [ 1 ] Bug #981471 - CVE-2013-4668 file-roller: path sanitization errors https://bugzilla.redhat.com/show_bug.cgi?id=981471 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update file-roller' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds