CVE-2013-4668
Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote attackers to create arbitrary files via a crafted archive that is not properly handled in a "Keep…
Does this matter?
Lower severity and a low EPSS score (4.31%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote attackers to create arbitrary files via a crafted archive that is not properly handled in a "Keep directory structure" action, related to fr-archive-libarchive.c and fr-window.c.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 4.31% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- file roller project/file roller · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2013-07/0039.htmlBroken Link
- http://lists.opensuse.org/opensuse-updates/2013-07/msg00095.htmlBroken Link
- http://secunia.com/advisories/54351Not Applicable, Third Party Advisory
- http://www.ocert.org/advisories/ocert-2013-001.htmlThird Party Advisory
- http://www.securityfocus.com/bid/61008Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1906-1Third Party Advisory
- https://git.gnome.org/browse/file-roller/commit/?id=b147281293a8307808475e102a14857055f81631Patch, Third Party Advisory
- http://archives.neohapsis.com/archives/bugtraq/2013-07/0039.htmlBroken Link
- http://lists.opensuse.org/opensuse-updates/2013-07/msg00095.htmlBroken Link
- http://secunia.com/advisories/54351Not Applicable, Third Party Advisory
- http://www.ocert.org/advisories/ocert-2013-001.htmlThird Party Advisory
- http://www.securityfocus.com/bid/61008Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1906-1Third Party Advisory
- https://git.gnome.org/browse/file-roller/commit/?id=b147281293a8307808475e102a14857055f81631Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.