Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia: 2021-0145 Critical: gnome-autoar Remote Code Execution

mageia
Calendar Grey March 4, 2021
Dist Mageia Esm H88
The latest GNOME Autoar patch resolves a vulnerability that might permit unauthorized code execution through manipulated archive file extraction.
Yiğit Can Yılmaz discovered that GNOME Autoar could extract files outside of the intended directory

Summary

Yiğit Can Yılmaz discovered that GNOME Autoar could extract files outside of the intended directory. If a user were tricked into extracting a specially crafted archive, a remote attacker could create files in arbitrary locations, possibly leading to code execution (CVE-2020-36241).

References

- https://bugs.mageia.org/show_bug.cgi?id=28454

- https://ubuntu.com/security/notices/USN-4733-1

- https://www.cve.org/CVERecord?id=CVE-2020-36241

Resolution

SRPMS

- 7/core/gnome-autoar-0.2.3-2.1.mga7

- 8/core/gnome-autoar-0.2.4-2.1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 04 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0111.html
Type: security
CVE: CVE-2020-36241

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here