An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.
{ "binaries": [ { "binary_version": "3.16.5-0ubuntu1.3", "binary_name": "file-roller" } ], "availability": "No subscription required" }
{ "binaries": [ { "binary_version": "3.28.0-1ubuntu1.1", "binary_name": "file-roller" } ], "availability": "No subscription required" }