It was discovered that GLib incorrectly handled certain symlinks when replacing files. If a user or automated system were tricked into extracting a specially crafted file with File Roller, a remote attacker could possibly create files outside of the intended directory.
{ "availability": "No subscription required", "binaries": [ { "binary_version": "2.48.2-0ubuntu4.8", "binary_name": "libglib2.0-0" }, { "binary_version": "2.48.2-0ubuntu4.8", "binary_name": "libglib2.0-0-refdbg" }, { "binary_version": "2.48.2-0ubuntu4.8", "binary_name": "libglib2.0-bin" }, { "binary_version": "2.48.2-0ubuntu4.8", "binary_name": "libglib2.0-data" }, { "binary_version": "2.48.2-0ubuntu4.8", "binary_name": "libglib2.0-dev" }, { "binary_version": "2.48.2-0ubuntu4.8", "binary_name": "libglib2.0-tests" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "2.56.4-0ubuntu0.18.04.8", "binary_name": "libglib2.0-0" }, { "binary_version": "2.56.4-0ubuntu0.18.04.8", "binary_name": "libglib2.0-bin" }, { "binary_version": "2.56.4-0ubuntu0.18.04.8", "binary_name": "libglib2.0-data" }, { "binary_version": "2.56.4-0ubuntu0.18.04.8", "binary_name": "libglib2.0-dev" }, { "binary_version": "2.56.4-0ubuntu0.18.04.8", "binary_name": "libglib2.0-dev-bin" }, { "binary_version": "2.56.4-0ubuntu0.18.04.8", "binary_name": "libglib2.0-tests" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_version": "2.64.6-1~ubuntu20.04.3", "binary_name": "libglib2.0-0" }, { "binary_version": "2.64.6-1~ubuntu20.04.3", "binary_name": "libglib2.0-bin" }, { "binary_version": "2.64.6-1~ubuntu20.04.3", "binary_name": "libglib2.0-data" }, { "binary_version": "2.64.6-1~ubuntu20.04.3", "binary_name": "libglib2.0-dev" }, { "binary_version": "2.64.6-1~ubuntu20.04.3", "binary_name": "libglib2.0-dev-bin" }, { "binary_version": "2.64.6-1~ubuntu20.04.3", "binary_name": "libglib2.0-tests" } ] }