Summary: | app-arch/file-roller: Path sanitization errors (CVE-2013-4668) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Agostino Sarubbo <ago> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | gnome |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | http://www.openwall.com/lists/oss-security/2013/07/08/1 | ||
Whiteboard: | B3 [noglsa] | ||
Package list: | Runtime testing required: | --- |
Description
Agostino Sarubbo
![]() We have 3.8.3 (masked), need 3.6.4. 3.6.4 has been bumped, and 3.8.3 was in portage already. The vulnerability description states that only >=file-roller-3.6 was affected, which for us is ~arch only, so it would appear that there is nothing to stabilize. The code paths for dealing with filenames were substantially rewritten between file-roller-3.4 and 3.6, and libarchive support was did not exist at all before 3.6. It is therefore difficult to check whether our stable file-roller version (2.32.2) might be affected by this or similar vulnerability. (It's possible that the report didn't mention it only because the report writer considered 2.32 to be obsolete.) +*file-roller-3.6.4 (15 Jul 2013) + + 15 Jul 2013; Alexandre Rostovtsev <tetromino@gentoo.org> + +file-roller-3.6.4.ebuild: + Version bump, fixes path traversal vulnerability (bug #476766, CVE-2013-4668, + thanks to Agostino Sarubbo). CVE-2013-4668 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4668): Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote attackers to create arbitrary files via a crafted archive that is not properly handled in a "Keep directory structure" action, related to fr-archive-libarchive.c and fr-window.c. Please remove affected versions so we can close this. + 27 Aug 2013; Pacho Ramos <pacho@gentoo.org> -file-roller-3.6.3.ebuild, + -file-roller-3.6.4.ebuild, -file-roller-3.8.2.ebuild, + -file-roller-3.8.3.ebuild, -files/3.1.2-packages.match: + Drop old + Thank you. Stable versions are unaffected, closing noglsa. |