It was discovered that engrampa, an archive manager for the MATE desktop environment was susceptible to path traversal when handling CPIO archives. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3741-1
File Roller could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-4927-1 April 26, 2021 file-roller vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: File Roller could be made to expose sensitive information. Software Description: - file-roller: archive manager for GNOME Details: It was discovered that File Roller incorrectly handled symlinks. An attacker could possibly use this issue to expose sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: file-roller 3.38.0-1ubuntu0.1 Ubuntu 20.04 LTS: file-roller 3.36.3-0ubuntu1.1 Ubuntu 18.04 LTS: file-roller 3.28.0-1ubuntu1.3 Ubuntu 16.04 LTS: file-roller 3.16.5-0ubuntu1.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4927-1 CVE-2020-36314 Package Information: https://launchpad.net/ubuntu/+source/file-roller/3.38.0-1ubuntu0.1 https://launchpad.net/ubuntu/+source/file-roller/3.36.3-0ubuntu1.1 https://launchpad.net/ubuntu/+source/file-roller/3.28.0-1ubuntu1.3 https://launchpad.net/ubuntu/+source/file-roller/3.16.5-0ubuntu1.5 . This document discusses Ubuntu Security Notice USN-4927-1 regarding a critical vulnerability in File Roller, allowing unauthorized access to sensitive data and urging users to update their installations to enhance system security against potential risks. File Roller, Information Exposure, Ubuntu Security Notice. . Severity: Important. LinuxSecurity.com Team
security fix for CVE-2020-24654. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-f04f41bcc9 2020-09-25 16:31:57.890800 --------------------------------------------------------------------------------Name : ark Product : Fedora 33 Version : 20.04.3 Release : 5.fc33 URL : https://apps.kde.org//utilities/ark/ Summary : Archive manager Description : Ark is a program for managing various archive formats. Archives can be viewed, extracted, created and modified from within Ark. The program can handle various formats such as tar, gzip, bzip2, zip, rar and lha (if appropriate command-line programs are installed). --------------------------------------------------------------------------------Update Information: security fix for CVE-2020-24654 --------------------------------------------------------------------------------ChangeLog: * Mon Aug 31 2020 Than Ngo - 20.04.3-5 - backport security fix for CVE-2020-24654 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-f04f41bcc9' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
security fix for CVE-2020-24654. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-c2f8a1e8a5 2020-09-07 17:12:41.698719 --------------------------------------------------------------------------------Name : ark Product : Fedora 32 Version : 20.04.3 Release : 5.fc32 URL : https://apps.kde.org//utilities/ark/ Summary : Archive manager Description : Ark is a program for managing various archive formats. Archives can be viewed, extracted, created and modified from within Ark. The program can handle various formats such as tar, gzip, bzip2, zip, rar and lha (if appropriate command-line programs are installed). --------------------------------------------------------------------------------Update Information: security fix for CVE-2020-24654 --------------------------------------------------------------------------------ChangeLog: * Mon Aug 31 2020 Than Ngo - 20.04.3-5 - backport security fix for CVE-2020-24654 * Sat Aug 1 2020 Fedora Release Engineering - 20.04.3-4 - Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-c2f8a1e8a5' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-e2fe8f0165 2020-08-13 01:38:09.348906 --------------------------------------------------------------------------------Name : ark Product : Fedora 32 Version : 20.04.3 Release : 3.fc32 URL : https://apps.kde.org//utilities/ark/ Summary : Archive manager Description : Ark is a program for managing various archive formats. Archives can be viewed, extracted, created and modified from within Ark. The program can handle various formats such as tar, gzip, bzip2, zip, rar and lha (if appropriate command-line programs are installed). --------------------------------------------------------------------------------Update Information: Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt --------------------------------------------------------------------------------ChangeLog: * Fri Jul 31 2020 Rex Dieter - 20.04.3-3 - backport security fix for CVE-2020-16116 * Mon Jul 27 2020 Fedora Release Engineering - 20.04.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Fri Jul 10 2020 Rex Dieter - 20.04.3-1 - 20.04.3 * Fri Jun 12 2020 Rex Dieter - 20.04.2-1 - 20.04.2 * Wed May 27 2020 Rex Dieter - 20.04.1-1 - 20.04.1 * Sat Mar 7 2020 Rex Dieter - 19.12.3-1 - 19.12.3 --------------------------------------------------------------------------------References: [ 1 ] Bug #1862464 - CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory https://bugzilla.redhat.com/show_bug.cgi?id=1862464 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-e2fe8f0165' at the command line. For more information,refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-cac5ae9b6e 2020-08-09 03:12:26.543960 --------------------------------------------------------------------------------Name : ark Product : Fedora 31 Version : 20.04.3 Release : 3.fc31 URL : https://apps.kde.org//utilities/ark/ Summary : Archive manager Description : Ark is a program for managing various archive formats. Archives can be viewed, extracted, created and modified from within Ark. The program can handle various formats such as tar, gzip, bzip2, zip, rar and lha (if appropriate command-line programs are installed). --------------------------------------------------------------------------------Update Information: Security update for CVE-2020-16116, https://kde.org/info/security/advisory-20200730-1.txt --------------------------------------------------------------------------------ChangeLog: * Fri Jul 31 2020 Rex Dieter - 20.04.3-3 - backport security fix for CVE-2020-16116 * Mon Jul 27 2020 Fedora Release Engineering - 20.04.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Fri Jul 10 2020 Rex Dieter - 20.04.3-1 - 20.04.3 * Fri Jun 12 2020 Rex Dieter - 20.04.2-1 - 20.04.2 * Wed May 27 2020 Rex Dieter - 20.04.1-1 - 20.04.1 * Sat Mar 7 2020 Rex Dieter - 19.12.3-1 - 19.12.3 * Tue Feb 4 2020 Rex Dieter - 19.12.2-1 - 19.12.2 * Fri Jan 31 2020 Rex Dieter - 19.12.1-1 - 19.12.1 * Tue Jan 28 2020 Fedora Release Engineering - 19.08.3-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Tue Nov 12 2019 Rex Dieter - 19.08.3-1 - 19.08.3 * Thu Oct 17 2019 Rex Dieter - 19.08.2-1 - 19.08.2 * Fri Oct 4 2019 Rex Dieter - 19.08.1-1 - 19.08.1 --------------------------------------------------------------------------------References: [ 1 ] Bug #1862464 -CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory https://bugzilla.redhat.com/show_bug.cgi?id=1862464 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-cac5ae9b6e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Dominik Penner discovered that the Ark archive manager did not sanitise extraction paths, which could result in maliciously crafted archives writing outside the extraction directory. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4738-1
File Roller could be made to expose sensitive information.. =========================================================================Ubuntu Security Notice USN-4332-2 April 27, 2020 file-roller vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.04 LTS Summary: File Roller could be made to expose sensitive information. Software Description: - file-roller: archive manager for GNOME Details: USN-4332-1 fixed vulnerabilities in File Roller. This update provides the corresponding update for Ubuntu 20.04 LTS. Original advisory details: It was discovered that File Roller incorrectly handled symlinks. An attacker could possibly use this issue to expose sensitive information. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: file-roller 3.36.1-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4332-2 https://ubuntu.com/security/notices/USN-4332-1 CVE-2020-11736 Package Information: https://launchpad.net/ubuntu/+source/file-roller/3.36.1-1ubuntu0.1 . Ubuntu Security Alert USN-4332-2 outlines a critical vulnerability in file-roller that may reveal confidential data. Discover measures to enhance your security today.. File Roller Vulnerability, Ubuntu Security Advisory, Information Exposure Issue. . Severity: Medium. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.