VYPR

File Roller

by GNOME Foundation

Source repositories

CVEs (5)

  • CVE-2016-7162HigSep 26, 2016
    risk 0.49cvss 7.5epss 0.03

    The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.

  • CVE-2026-78322MedAug 25, 2026
    risk 0.35cvss 6.5epss 0.01

    A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with an excessively long path, file-roller's progress-line parsing copies the path into a fixed-size stack buffer using an unbounded string copy. This can trigger a…

  • CVE-2020-11736LowApr 13, 2020
    risk 0.25cvss 3.9epss 0.01

    fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

  • CVE-2019-16680MedSep 21, 2019
    risk 0.21cvss 4.3epss 0.02

    An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.

  • CVE-2020-36314LowApr 7, 2021
    risk 0.18cvss 3.9epss 0.01

    fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of…