Vulnerability Details CVE-2020-36314
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.4%
CVSS Severity
CVSS v3 Score 3.9
CVSS v2 Score 2.6
Products affected by CVE-2020-36314
-
cpe:2.3:a:gnome:file-roller:2.32.2
-
cpe:2.3:a:gnome:file-roller:3.0.1
-
cpe:2.3:a:gnome:file-roller:3.0.2
-
cpe:2.3:a:gnome:file-roller:3.1.1
-
cpe:2.3:a:gnome:file-roller:3.1.2
-
cpe:2.3:a:gnome:file-roller:3.1.90
-
cpe:2.3:a:gnome:file-roller:3.1.91
-
cpe:2.3:a:gnome:file-roller:3.1.92
-
cpe:2.3:a:gnome:file-roller:3.10.0
-
cpe:2.3:a:gnome:file-roller:3.10.1
-
cpe:2.3:a:gnome:file-roller:3.10.2
-
cpe:2.3:a:gnome:file-roller:3.10.2.1
-
cpe:2.3:a:gnome:file-roller:3.11.1
-
cpe:2.3:a:gnome:file-roller:3.11.2
-
cpe:2.3:a:gnome:file-roller:3.11.3
-
cpe:2.3:a:gnome:file-roller:3.11.4
-
cpe:2.3:a:gnome:file-roller:3.11.5
-
cpe:2.3:a:gnome:file-roller:3.11.90
-
cpe:2.3:a:gnome:file-roller:3.11.91
-
cpe:2.3:a:gnome:file-roller:3.11.92
-
cpe:2.3:a:gnome:file-roller:3.12.0
-
cpe:2.3:a:gnome:file-roller:3.12.1
-
cpe:2.3:a:gnome:file-roller:3.12.2
-
cpe:2.3:a:gnome:file-roller:3.13.1
-
cpe:2.3:a:gnome:file-roller:3.13.2
-
cpe:2.3:a:gnome:file-roller:3.13.91
-
cpe:2.3:a:gnome:file-roller:3.13.92
-
cpe:2.3:a:gnome:file-roller:3.14.0
-
cpe:2.3:a:gnome:file-roller:3.14.1
-
cpe:2.3:a:gnome:file-roller:3.14.2
-
cpe:2.3:a:gnome:file-roller:3.15.1
-
cpe:2.3:a:gnome:file-roller:3.15.2
-
cpe:2.3:a:gnome:file-roller:3.15.90
-
cpe:2.3:a:gnome:file-roller:3.15.91
-
cpe:2.3:a:gnome:file-roller:3.15.92
-
cpe:2.3:a:gnome:file-roller:3.16.0
-
cpe:2.3:a:gnome:file-roller:3.16.1
-
cpe:2.3:a:gnome:file-roller:3.16.2
-
cpe:2.3:a:gnome:file-roller:3.16.3
-
cpe:2.3:a:gnome:file-roller:3.16.4
-
cpe:2.3:a:gnome:file-roller:3.16.5
-
cpe:2.3:a:gnome:file-roller:3.19.1
-
cpe:2.3:a:gnome:file-roller:3.19.90
-
cpe:2.3:a:gnome:file-roller:3.19.91
-
cpe:2.3:a:gnome:file-roller:3.2.0
-
cpe:2.3:a:gnome:file-roller:3.2.1
-
cpe:2.3:a:gnome:file-roller:3.2.2
-
cpe:2.3:a:gnome:file-roller:3.20.0
-
cpe:2.3:a:gnome:file-roller:3.20.1
-
cpe:2.3:a:gnome:file-roller:3.20.2
-
cpe:2.3:a:gnome:file-roller:3.20.3
-
cpe:2.3:a:gnome:file-roller:3.20.4
-
cpe:2.3:a:gnome:file-roller:3.21.90
-
cpe:2.3:a:gnome:file-roller:3.21.91
-
cpe:2.3:a:gnome:file-roller:3.22.0
-
cpe:2.3:a:gnome:file-roller:3.22.1
-
cpe:2.3:a:gnome:file-roller:3.22.2
-
cpe:2.3:a:gnome:file-roller:3.22.3
-
cpe:2.3:a:gnome:file-roller:3.23.91
-
cpe:2.3:a:gnome:file-roller:3.23.92
-
cpe:2.3:a:gnome:file-roller:3.24.0
-
cpe:2.3:a:gnome:file-roller:3.24.1
-
cpe:2.3:a:gnome:file-roller:3.25.1
-
cpe:2.3:a:gnome:file-roller:3.25.91
-
cpe:2.3:a:gnome:file-roller:3.26.0
-
cpe:2.3:a:gnome:file-roller:3.26.1
-
cpe:2.3:a:gnome:file-roller:3.26.2
-
cpe:2.3:a:gnome:file-roller:3.27.1
-
cpe:2.3:a:gnome:file-roller:3.27.90
-
cpe:2.3:a:gnome:file-roller:3.27.91
-
cpe:2.3:a:gnome:file-roller:3.28.0
-
cpe:2.3:a:gnome:file-roller:3.28.1
-
cpe:2.3:a:gnome:file-roller:3.29.1
-
cpe:2.3:a:gnome:file-roller:3.29.90
-
cpe:2.3:a:gnome:file-roller:3.29.91
-
cpe:2.3:a:gnome:file-roller:3.3.1
-
cpe:2.3:a:gnome:file-roller:3.3.2
-
cpe:2.3:a:gnome:file-roller:3.3.3
-
cpe:2.3:a:gnome:file-roller:3.3.90
-
cpe:2.3:a:gnome:file-roller:3.3.91
-
cpe:2.3:a:gnome:file-roller:3.3.92
-
cpe:2.3:a:gnome:file-roller:3.30.0
-
cpe:2.3:a:gnome:file-roller:3.30.1
-
cpe:2.3:a:gnome:file-roller:3.31.1
-
cpe:2.3:a:gnome:file-roller:3.31.2
-
cpe:2.3:a:gnome:file-roller:3.31.90
-
cpe:2.3:a:gnome:file-roller:3.31.91
-
cpe:2.3:a:gnome:file-roller:3.31.92
-
cpe:2.3:a:gnome:file-roller:3.32.0
-
cpe:2.3:a:gnome:file-roller:3.32.1
-
cpe:2.3:a:gnome:file-roller:3.32.2
-
cpe:2.3:a:gnome:file-roller:3.32.3
-
cpe:2.3:a:gnome:file-roller:3.32.4
-
cpe:2.3:a:gnome:file-roller:3.35.1
-
cpe:2.3:a:gnome:file-roller:3.35.90
-
cpe:2.3:a:gnome:file-roller:3.35.91
-
cpe:2.3:a:gnome:file-roller:3.35.92
-
cpe:2.3:a:gnome:file-roller:3.36.0
-
cpe:2.3:a:gnome:file-roller:3.36.1
-
cpe:2.3:a:gnome:file-roller:3.4.0
-
cpe:2.3:a:gnome:file-roller:3.4.1
-
cpe:2.3:a:gnome:file-roller:3.4.2
-
cpe:2.3:a:gnome:file-roller:3.5.1
-
cpe:2.3:a:gnome:file-roller:3.5.2
-
cpe:2.3:a:gnome:file-roller:3.5.3
-
cpe:2.3:a:gnome:file-roller:3.5.4
-
cpe:2.3:a:gnome:file-roller:3.5.90
-
cpe:2.3:a:gnome:file-roller:3.5.91
-
cpe:2.3:a:gnome:file-roller:3.5.92
-
cpe:2.3:a:gnome:file-roller:3.6.0
-
cpe:2.3:a:gnome:file-roller:3.6.1
-
cpe:2.3:a:gnome:file-roller:3.6.1.1
-
cpe:2.3:a:gnome:file-roller:3.6.2
-
cpe:2.3:a:gnome:file-roller:3.6.3
-
cpe:2.3:a:gnome:file-roller:3.6.4
-
cpe:2.3:a:gnome:file-roller:3.7.1
-
cpe:2.3:a:gnome:file-roller:3.7.2
-
cpe:2.3:a:gnome:file-roller:3.7.3
-
cpe:2.3:a:gnome:file-roller:3.7.90
-
cpe:2.3:a:gnome:file-roller:3.7.91
-
cpe:2.3:a:gnome:file-roller:3.7.92
-
cpe:2.3:a:gnome:file-roller:3.8.0
-
cpe:2.3:a:gnome:file-roller:3.8.1
-
cpe:2.3:a:gnome:file-roller:3.8.2
-
cpe:2.3:a:gnome:file-roller:3.8.3
-
cpe:2.3:a:gnome:file-roller:3.8.4
-
cpe:2.3:a:gnome:file-roller:3.9.1
-
cpe:2.3:a:gnome:file-roller:3.9.2
-
cpe:2.3:a:gnome:file-roller:3.9.3
-
cpe:2.3:a:gnome:file-roller:3.9.4
-
cpe:2.3:a:gnome:file-roller:3.9.90
-
cpe:2.3:a:gnome:file-roller:3.9.91
-
cpe:2.3:a:gnome:file-roller:3.9.92
-
cpe:2.3:o:fedoraproject:fedora:34