Description: "autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241." Patch: https://gitlab.gnome.org/GNOME/gnome-autoar/-/commit/8109c368c6cfdb593faaf698c2bf5da32bb1ace4
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=51c21938ec3fde06d235145eb7f39bc2d7002869 commit 51c21938ec3fde06d235145eb7f39bc2d7002869 Author: Matt Turner <mattst88@gentoo.org> AuthorDate: 2021-03-20 23:40:58 +0000 Commit: Matt Turner <mattst88@gentoo.org> CommitDate: 2021-03-20 23:43:19 +0000 app-arch/gnome-autoar: Version bump to 0.3.1 Bug: https://bugs.gentoo.org/777126 Signed-off-by: Matt Turner <mattst88@gentoo.org> app-arch/gnome-autoar/Manifest | 1 + app-arch/gnome-autoar/gnome-autoar-0.3.1.ebuild | 43 +++++++++++++++++++++++++ 2 files changed, 44 insertions(+)
Thank you! Please proceed with stabilization when ready.
Ping
arm64 done
amd64 stable
x86 stable. Maintainer(s), please cleanup. Security, please add it to the existing request, or file a new one.
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8089d0f5e111b06dc93296016f2bdde74d354c8e commit 8089d0f5e111b06dc93296016f2bdde74d354c8e Author: Matt Turner <mattst88@gentoo.org> AuthorDate: 2021-03-29 15:22:35 +0000 Commit: Matt Turner <mattst88@gentoo.org> CommitDate: 2021-03-29 15:22:55 +0000 app-arch/gnome-autoar: Drop old versions Bug: https://bugs.gentoo.org/777126 Signed-off-by: Matt Turner <mattst88@gentoo.org> app-arch/gnome-autoar/Manifest | 1 - app-arch/gnome-autoar/gnome-autoar-0.3.0.ebuild | 43 ------------------------- 2 files changed, 44 deletions(-)
Thanks!
New GLSA request filed.
This issue was resolved and addressed in GLSA 202105-10 at https://security.gentoo.org/glsa/202105-10 by GLSA coordinator Thomas Deutschmann (whissi).