Advisories ยป MGASA-2020-0218

Updated file-roller packages fix security vulnerability

Publication date: 24 May 2020
Modification date: 24 May 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-11736

Description

Updated the file-roller package in order to fix a security vulnerability:

fr-archive-libarchive.c: File Roller lacks a check of whether a file's
parent is a symlink to a directory outside of the intended extraction
location. Thus, directory traversal is not prevented (CVE-2020-11736).
                

References

SRPMS

7/core