Lucene search

K
osvGoogleOSV:USN-4937-1
HistoryMay 06, 2021 - 11:15 a.m.

gnome-autoar vulnerability

2021-05-0611:15:45
Google
osv.dev
8

6.9 Medium

AI Score

Confidence

Low

0.0005 Low

EPSS

Percentile

17.4%

Ondrej Holy discovered that GNOME Autoar could extract files outside of the
intended directory. If a user were tricked into extracting a specially
crafted archive, a remote attacker could create files in arbitrary
locations, possibly leading to code execution.