Lucene search

K
ubuntuUbuntuUSN-1906-1
HistoryJul 16, 2013 - 12:00 a.m.

File Roller vulnerability

2013-07-1600:00:00
ubuntu.com
27

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.3 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.6%

Releases

  • Ubuntu 13.04
  • Ubuntu 12.10

Packages

  • file-roller - archive manager for GNOME

Details

Yorick Koster discovered that File Roller incorrectly sanitized paths. If a
user were tricked into extracting a specially-crafted archive, an attacker
could create and overwrite files outside of the extraction directory.

OSVersionArchitecturePackageVersionFilename
Ubuntu13.04noarchfile-roller< 3.6.3-1ubuntu4.1UNKNOWN
Ubuntu12.10noarchfile-roller< 3.6.1.1-0ubuntu1.2UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:N/I:P/A:N

6.3 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.6%