High severity7.5NVD Advisory· Published Sep 26, 2016· Updated May 6, 2026
CVE-2016-7162
CVE-2016-7162
Description
The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- git.gnome.org/browse/file-roller/commit/nvdPatch
- bugzilla.gnome.org/show_bug.cginvdExploitIssue Tracking
- ftp.gnome.org/mirror/gnome.org/sources/file-roller/3.20/file-roller-3.20.3.newsnvdThird Party Advisory
- www.openwall.com/lists/oss-security/2016/09/08/4nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/92896nvdThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-3074-1nvdThird Party Advisory
- ftp.gnome.org/mirror/gnome.org/sources/file-roller/3.21/file-roller-3.21.90.newsnvdBroken Link
News mentions
0No linked articles in our index yet.