Path Traversal Vulnerability in GNOME File-Roller Affects Multiple Versions
CVE-2019-16680
4.3MEDIUM
Summary
A vulnerability in GNOME File-Roller allows attackers to exploit a path traversal flaw when extracting files from a TAR archive. This issue, present in versions before 3.29.91, permits a crafted filename with a './../' sequence to overwrite files on the system, potentially leading to data loss or system compromise.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved