Vulnerability Details CVE-2019-16680
An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 80.8%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 2.6
Products affected by CVE-2019-16680
-
cpe:2.3:a:gnome:file-roller:2.32.2
-
cpe:2.3:a:gnome:file-roller:3.0.1
-
cpe:2.3:a:gnome:file-roller:3.0.2
-
cpe:2.3:a:gnome:file-roller:3.1.1
-
cpe:2.3:a:gnome:file-roller:3.1.2
-
cpe:2.3:a:gnome:file-roller:3.1.90
-
cpe:2.3:a:gnome:file-roller:3.1.91
-
cpe:2.3:a:gnome:file-roller:3.1.92
-
cpe:2.3:a:gnome:file-roller:3.10.0
-
cpe:2.3:a:gnome:file-roller:3.10.1
-
cpe:2.3:a:gnome:file-roller:3.10.2
-
cpe:2.3:a:gnome:file-roller:3.10.2.1
-
cpe:2.3:a:gnome:file-roller:3.11.1
-
cpe:2.3:a:gnome:file-roller:3.11.2
-
cpe:2.3:a:gnome:file-roller:3.11.3
-
cpe:2.3:a:gnome:file-roller:3.11.4
-
cpe:2.3:a:gnome:file-roller:3.11.5
-
cpe:2.3:a:gnome:file-roller:3.11.90
-
cpe:2.3:a:gnome:file-roller:3.11.91
-
cpe:2.3:a:gnome:file-roller:3.11.92
-
cpe:2.3:a:gnome:file-roller:3.12.0
-
cpe:2.3:a:gnome:file-roller:3.12.1
-
cpe:2.3:a:gnome:file-roller:3.12.2
-
cpe:2.3:a:gnome:file-roller:3.13.1
-
cpe:2.3:a:gnome:file-roller:3.13.2
-
cpe:2.3:a:gnome:file-roller:3.13.91
-
cpe:2.3:a:gnome:file-roller:3.13.92
-
cpe:2.3:a:gnome:file-roller:3.14.0
-
cpe:2.3:a:gnome:file-roller:3.14.1
-
cpe:2.3:a:gnome:file-roller:3.14.2
-
cpe:2.3:a:gnome:file-roller:3.15.1
-
cpe:2.3:a:gnome:file-roller:3.15.2
-
cpe:2.3:a:gnome:file-roller:3.15.90
-
cpe:2.3:a:gnome:file-roller:3.15.91
-
cpe:2.3:a:gnome:file-roller:3.15.92
-
cpe:2.3:a:gnome:file-roller:3.16.0
-
cpe:2.3:a:gnome:file-roller:3.16.1
-
cpe:2.3:a:gnome:file-roller:3.16.2
-
cpe:2.3:a:gnome:file-roller:3.16.3
-
cpe:2.3:a:gnome:file-roller:3.16.4
-
cpe:2.3:a:gnome:file-roller:3.16.5
-
cpe:2.3:a:gnome:file-roller:3.19.1
-
cpe:2.3:a:gnome:file-roller:3.19.90
-
cpe:2.3:a:gnome:file-roller:3.19.91
-
cpe:2.3:a:gnome:file-roller:3.2.0
-
cpe:2.3:a:gnome:file-roller:3.2.1
-
cpe:2.3:a:gnome:file-roller:3.2.2
-
cpe:2.3:a:gnome:file-roller:3.20.0
-
cpe:2.3:a:gnome:file-roller:3.20.1
-
cpe:2.3:a:gnome:file-roller:3.20.2
-
cpe:2.3:a:gnome:file-roller:3.20.3
-
cpe:2.3:a:gnome:file-roller:3.20.4
-
cpe:2.3:a:gnome:file-roller:3.21.90
-
cpe:2.3:a:gnome:file-roller:3.21.91
-
cpe:2.3:a:gnome:file-roller:3.22.0
-
cpe:2.3:a:gnome:file-roller:3.22.1
-
cpe:2.3:a:gnome:file-roller:3.22.2
-
cpe:2.3:a:gnome:file-roller:3.22.3
-
cpe:2.3:a:gnome:file-roller:3.23.91
-
cpe:2.3:a:gnome:file-roller:3.23.92
-
cpe:2.3:a:gnome:file-roller:3.24.0
-
cpe:2.3:a:gnome:file-roller:3.24.1
-
cpe:2.3:a:gnome:file-roller:3.25.1
-
cpe:2.3:a:gnome:file-roller:3.25.91
-
cpe:2.3:a:gnome:file-roller:3.26.0
-
cpe:2.3:a:gnome:file-roller:3.26.1
-
cpe:2.3:a:gnome:file-roller:3.26.2
-
cpe:2.3:a:gnome:file-roller:3.27.1
-
cpe:2.3:a:gnome:file-roller:3.27.90
-
cpe:2.3:a:gnome:file-roller:3.27.91
-
cpe:2.3:a:gnome:file-roller:3.28.0
-
cpe:2.3:a:gnome:file-roller:3.28.1
-
cpe:2.3:a:gnome:file-roller:3.29.1
-
cpe:2.3:a:gnome:file-roller:3.29.90
-
cpe:2.3:a:gnome:file-roller:3.3.1
-
cpe:2.3:a:gnome:file-roller:3.3.2
-
cpe:2.3:a:gnome:file-roller:3.3.3
-
cpe:2.3:a:gnome:file-roller:3.3.90
-
cpe:2.3:a:gnome:file-roller:3.3.91
-
cpe:2.3:a:gnome:file-roller:3.3.92
-
cpe:2.3:a:gnome:file-roller:3.4.0
-
cpe:2.3:a:gnome:file-roller:3.4.1
-
cpe:2.3:a:gnome:file-roller:3.4.2
-
cpe:2.3:a:gnome:file-roller:3.5.1
-
cpe:2.3:a:gnome:file-roller:3.5.2
-
cpe:2.3:a:gnome:file-roller:3.5.3
-
cpe:2.3:a:gnome:file-roller:3.5.4
-
cpe:2.3:a:gnome:file-roller:3.5.90
-
cpe:2.3:a:gnome:file-roller:3.5.91
-
cpe:2.3:a:gnome:file-roller:3.5.92
-
cpe:2.3:a:gnome:file-roller:3.6.0
-
cpe:2.3:a:gnome:file-roller:3.6.1
-
cpe:2.3:a:gnome:file-roller:3.6.1.1
-
cpe:2.3:a:gnome:file-roller:3.6.2
-
cpe:2.3:a:gnome:file-roller:3.6.3
-
cpe:2.3:a:gnome:file-roller:3.6.4
-
cpe:2.3:a:gnome:file-roller:3.7.1
-
cpe:2.3:a:gnome:file-roller:3.7.2
-
cpe:2.3:a:gnome:file-roller:3.7.3
-
cpe:2.3:a:gnome:file-roller:3.7.90
-
cpe:2.3:a:gnome:file-roller:3.7.91
-
cpe:2.3:a:gnome:file-roller:3.7.92
-
cpe:2.3:a:gnome:file-roller:3.8.0
-
cpe:2.3:a:gnome:file-roller:3.8.1
-
cpe:2.3:a:gnome:file-roller:3.8.2
-
cpe:2.3:a:gnome:file-roller:3.8.3
-
cpe:2.3:a:gnome:file-roller:3.8.4
-
cpe:2.3:a:gnome:file-roller:3.9.1
-
cpe:2.3:a:gnome:file-roller:3.9.2
-
cpe:2.3:a:gnome:file-roller:3.9.3
-
cpe:2.3:a:gnome:file-roller:3.9.4
-
cpe:2.3:a:gnome:file-roller:3.9.90
-
cpe:2.3:a:gnome:file-roller:3.9.91
-
cpe:2.3:a:gnome:file-roller:3.9.92
-
cpe:2.3:o:canonical:ubuntu_linux:16.04
-
cpe:2.3:o:canonical:ubuntu_linux:18.04
-
cpe:2.3:o:debian:debian_linux:8.0
-
cpe:2.3:o:debian:debian_linux:9.0
-
cpe:2.3:o:redhat:enterprise_linux:7.0
-
cpe:2.3:o:redhat:enterprise_linux:8.0