Advisories ยป MGASA-2021-0274

Updated gnome-autoar packages fix a security vulnerability

Publication date: 23 Jun 2021
Modification date: 23 Jun 2021
Type: security
Affected Mageia releases : 7 , 8
CVE: CVE-2021-28650

Description

gnome-autoar: directory traversal during extraction because it lacks a check
of whether a file's parent is a symlink in certain complex situations
(CVE-2021-28650).

Also the previous update (Bug 28454) introduced a regression, fixed here.
                

References

SRPMS

7/core

8/core