An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
],
"vendor_product": "canonical:ubuntu_linux",
"extracted_events": [
{
"introduced": "16.04"
},
{
"last_affected": "16.04"
},
{
"introduced": "18.04"
},
{
"last_affected": "18.04"
}
],
"source": "CPE_STRING"
},
{
"cpes": [
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"vendor_product": "debian:debian_linux",
"extracted_events": [
{
"introduced": "8.0"
},
{
"last_affected": "8.0"
},
{
"introduced": "9.0"
},
{
"last_affected": "9.0"
}
],
"source": "CPE_STRING"
},
{
"cpes": [
"cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*",
"cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*"
],
"vendor_product": "redhat:enterprise_linux",
"extracted_events": [
{
"introduced": "7.0"
},
{
"last_affected": "7.0"
},
{
"introduced": "8.0"
},
{
"last_affected": "8.0"
}
],
"source": "CPE_STRING"
}
]
}{
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.29.91"
}
],
"cpe": "cpe:2.3:a:gnome:file-roller:*:*:*:*:*:*:*:*"
}{
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "3.29.91"
}
],
"cpe": "cpe:2.3:a:gnome:file-roller:*:*:*:*:*:*:*:*"
}"2026-07-08T17:56:42Z"
[
{
"signature_version": "v1",
"target": {
"file": "src/glib-utils.c",
"function": "sanitize_filename"
},
"id": "CVE-2019-16680-0aa778df",
"signature_type": "Function",
"deprecated": false,
"digest": {
"function_hash": "27155979717750704031034549997628743833",
"length": 444.0
},
"source": "https://gitlab.gnome.org/gnome/file-roller@57268e51e59b61c9e3125eb0f65551c7084297e2"
},
{
"signature_version": "v1",
"target": {
"file": "src/glib-utils.c"
},
"id": "CVE-2019-16680-a60e9b0a",
"signature_type": "Line",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"138656517418615610897130002064559785166",
"247896318390256146051722219473642331694",
"198896843324868053886547451836575139848",
"113159501639207269924903206868110738369"
]
},
"source": "https://gitlab.gnome.org/gnome/file-roller@57268e51e59b61c9e3125eb0f65551c7084297e2"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-16680.json"