PublicDateAtUSN: 2019-09-21 Candidate: CVE-2019-16680 PublicDate: 2019-09-21 21:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16680 https://bugzilla.gnome.org/show_bug.cgi?id=794337 https://gitlab.gnome.org/GNOME/file-roller/commit/57268e51e59b61c9e3125eb0f65551c7084297e2 https://gitlab.gnome.org/GNOME/file-roller/commit/e8fb3e24dae711e4fb0d6777e0016cdda8787bc1 https://ubuntu.com/security/notices/USN-4139-1 Description: An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: leosilva CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N [4.3 MEDIUM] Patches_file-roller: upstream_file-roller: released (3.30.0-1) precise/esm_file-roller: DNE trusty_file-roller: ignored (out of standard support) trusty/esm_file-roller: DNE xenial_file-roller: released (3.16.5-0ubuntu1.3) esm-infra/xenial_file-roller: released (3.16.5-0ubuntu1.3) bionic_file-roller: released (3.28.0-1ubuntu1.1) disco_file-roller: not-affected (3.32.1-1) devel_file-roller: not-affected