CVE-2013-4668
Last modified
CVE-2013-4668 is a vulnerability of currently unknown severity. Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote attackers to create arbitrary files via a crafted archive that is not properly handled in a "Keep directory structure" action, related to fr-archive-libarchive.c and fr-window.c.. EPSS estimates a 4.31% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote attackers to create arbitrary files via a crafted archive that is not properly handled in a "Keep directory structure" action, related to fr-archive-libarchive.c and fr-window.c.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| File Roller Project | File Roller | >= 3.6.0, < 3.6.4 |
| File Roller Project | File Roller | >= 3.8.0, < 3.8.3 |
| File Roller Project | File Roller | >= 3.9.1, < 3.9.3 |
| Canonical | Ubuntu Linux | 12.10 |
| Canonical | Ubuntu Linux | 13.04 |
References
- http://secunia.com/advisories/54351Not Applicable, Third Party Advisory
- http://www.ocert.org/advisories/ocert-2013-001.htmlThird Party Advisory
- http://www.securityfocus.com/bid/61008Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1906-1Third Party Advisory
- https://git.gnome.org/browse/file-roller/commit/?id=b147281293a8307808475e102a14857055f81631Patch, Third Party Advisory
- http://secunia.com/advisories/54351Not Applicable, Third Party Advisory
- http://www.ocert.org/advisories/ocert-2013-001.htmlThird Party Advisory
- http://www.securityfocus.com/bid/61008Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1906-1Third Party Advisory
- https://git.gnome.org/browse/file-roller/commit/?id=b147281293a8307808475e102a14857055f81631Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-4668?
How severe is CVE-2013-4668?
How do I fix CVE-2013-4668?
Are you affected by CVE-2013-4668?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
