The gfileremovedirectory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "3.5.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.1.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.3"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.8.0"
},
{
"introduced": "0"
},
{
"last_affected": "3.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.8.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.8.3"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.3"
},
{
"introduced": "0"
},
{
"last_affected": "3.10"
},
{
"introduced": "0"
},
{
"last_affected": "3.20"
},
{
"introduced": "0"
},
{
"last_affected": "3.20.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.20.2"
}
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7162.json"
[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "14.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "16.04"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.9.0"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.15"
}
]
}
]