Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
A vulnerability has been found in GNOME Autoar that could allow a remote attacker to execute arbitrary code.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202105-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: GNOME Autoar: User-assisted execution of arbitrary code Date: May 26, 2021 Bugs: #768828, #777126 ID: 202105-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= A vulnerability has been found in GNOME Autoar that could allow a remote attacker to execute arbitrary code. Background ========= GNOME Autoar provides functions and widgets for GNOME applications which want to use archives as a method to transfer directories over the internet. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 app-arch/gnome-autoar < 0.3.1 > = 0.3.1 Description ========== It was discovered that GNOME Autoar could extract files outside of the intended directory. Impact ===== A remote attacker could entice a user to open a specially crafted archive using GNOME Autoar, possibly resulting in execution of arbitrary code with the privileges of the process or a Denial of Service condition. Workaround ========= There is no known workaround at this time. Resolution ========= All GNOME Autoar users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =app-arch/gnome-autoar-0.3.1" References ========= [ 1 ] CVE-2020-36241 https://nvd.nist.gov/vuln/detail/CVE-2020-36241 [ 2 ] CVE-2021-28650 https://nvd.nist.gov/vuln/detail/CVE-2021-28650 Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202105-10 Concerns? ======== Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Yiğit Can Yılmaz discovered that GNOME Autoar could extract files outside of the intended directory. If a user were tricked into extracting a specially crafted archive, a remote attacker could create files in arbitrary locations, possibly leading to code execution (CVE-2020-36241). . MGASA-2021-0111 - Updated gnome-autoar packages fix security vulnerability Publication date: 04 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0111.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2020-36241 Yiğit Can Yılmaz discovered that GNOME Autoar could extract files outside of the intended directory. If a user were tricked into extracting a specially crafted archive, a remote attacker could create files in arbitrary locations, possibly leading to code execution (CVE-2020-36241). References: - https://bugs.mageia.org/show_bug.cgi?id=28454 - https://ubuntu.com/security/notices/USN-4733-1 - https://www.cve.org/CVERecord?id=CVE-2020-36241 SRPMS: - 7/core/gnome-autoar-0.2.3-2.1.mga7 - 8/core/gnome-autoar-0.2.4-2.1.mga8 . The latest GNOME Autoar patch resolves a vulnerability that might permit unauthorized code execution through manipulated archive file extraction.. Mageia Security Update, GNOME Autoar, Code Execution Exploit. . Severity: Critical. LinuxSecurity.com Team
GNOME Autoar could be made to overwrite files.. =========================================================================Ubuntu Security Notice USN-4733-1 February 11, 2021 gnome-autoar vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 20.10 - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: GNOME Autoar could be made to overwrite files. Software Description: - gnome-autoar: Archive integration support for GNOME Details: Yiğit Can Yılmaz discovered that GNOME Autoar could extract files outside of the intended directory. If a user were tricked into extracting a specially crafted archive, a remote attacker could create files in arbitrary locations, possibly leading to code execution. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 20.10: libgnome-autoar-0-0 0.2.4-2ubuntu0.1 libgnome-autoar-gtk-0-0 0.2.4-2ubuntu0.1 Ubuntu 20.04 LTS: libgnome-autoar-0-0 0.2.3-2ubuntu0.1 libgnome-autoar-gtk-0-0 0.2.3-2ubuntu0.1 Ubuntu 18.04 LTS: libgnome-autoar-0-0 0.2.3-1ubuntu0.1 libgnome-autoar-gtk-0-0 0.2.3-1ubuntu0.1 After a standard system update you need to restart your session to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4733-1 CVE-2020-36241 Package Information: https://launchpad.net/ubuntu/+source/gnome-autoar/0.2.4-2ubuntu0.1 https://launchpad.net/ubuntu/+source/gnome-autoar/0.2.3-2ubuntu0.1 https://launchpad.net/ubuntu/+source/gnome-autoar/0.2.3-1ubuntu0.1 . Ubuntu Security Announcement USN-4733-1 informs about a GNOME Autoar vulnerability that could result in unintended file replacements, along with crucial updates to mitigate security threats. File Overwrite,Gnome Autoar,Security Updates,Ubuntu. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.