Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Mageia: 2021-0145 Critical: gnome-autoar Remote Code Execution

mageia
Calendar Grey March 4, 2021
Scroller Mageia
The latest GNOME Autoar patch resolves a vulnerability that might permit unauthorized code execution through manipulated archive file extraction.
Yiğit Can Yılmaz discovered that GNOME Autoar could extract files outside of the intended directory

Summary

Yiğit Can Yılmaz discovered that GNOME Autoar could extract files outside of the intended directory. If a user were tricked into extracting a specially crafted archive, a remote attacker could create files in arbitrary locations, possibly leading to code execution (CVE-2020-36241).

References

- https://bugs.mageia.org/show_bug.cgi?id=28454

- https://ubuntu.com/security/notices/USN-4733-1

- https://www.cve.org/CVERecord?id=CVE-2020-36241

Resolution

SRPMS

- 7/core/gnome-autoar-0.2.3-2.1.mga7

- 8/core/gnome-autoar-0.2.4-2.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 04 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0111.html
Type: security
CVE: CVE-2020-36241

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.