Ubuntu alert USN-3074-1 (file-roller)
| From: | Tyler Hicks <tyhicks@canonical.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-3074-1] File Roller vulnerability | |
| Date: | Thu, 8 Sep 2016 16:56:23 -0500 | |
| Message-ID: | <20160908215622.GA17124@boyd> |
========================================================================== Ubuntu Security Notice USN-3074-1 September 08, 2016 file-roller vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: File Roller could be made to delete files. Software Description: - file-roller: archive manager for GNOME Details: It was discovered that File Roller incorrectly handled symlinks. If a user were tricked into extracting a specially-crafted archive, an attacker could delete files outside of the extraction directory. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: file-roller 3.16.5-0ubuntu1.2 Ubuntu 14.04 LTS: file-roller 3.10.2.1-0ubuntu4.2 In general, a standard system update will make all the necessary changes. References: http://www.ubuntu.com/usn/usn-3074-1 CVE-2016-7162, https://launchpad.net/bugs/1171236 Package Information: https://launchpad.net/ubuntu/+source/file-roller/3.16.5-0... https://launchpad.net/ubuntu/+source/file-roller/3.10.2.1... -- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security...
