Updated file-roller packages fix security vulnerability
Publication date: 24 May 2020Modification date: 24 May 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-11736
Description
Updated the file-roller package in order to fix a security vulnerability: fr-archive-libarchive.c: File Roller lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location. Thus, directory traversal is not prevented (CVE-2020-11736).
References
SRPMS
7/core
- file-roller-3.32.1-2.1.mga7