An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.16.5-0ubuntu1.3", "binary_name": "file-roller" }, { "binary_version": "3.16.5-0ubuntu1.3", "binary_name": "file-roller-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "3.28.0-1ubuntu1.1", "binary_name": "file-roller" }, { "binary_version": "3.28.0-1ubuntu1.1", "binary_name": "file-roller-dbgsym" } ] }