-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2020.1369
                        file-roller security update
                               20 April 2020

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           file-roller
Publisher:         Debian
Operating System:  Debian GNU/Linux 8
                   UNIX variants (UNIX, Linux, OSX)
Impact/Access:     Create Arbitrary Files   -- Existing Account
                   Access Confidential Data -- Existing Account
Resolution:        Patch/Upgrade
CVE Names:         CVE-2020-11736  

Original Bulletin: 
   https://www.debian.org/lts/security/2020/dla-2180

Comment: This advisory references vulnerabilities in products which run on 
         platforms other than Debian. It is recommended that administrators 
         running file-roller check for an updated version of the software for
         their operating system.

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Package        : file-roller
Version        : 3.14.1-1+deb8u2
CVE ID         : CVE-2020-11736
Debian Bug     : 956638


fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows
Directory Traversal during extraction because it lacks a check of
whether a file's parent is a symlink to a directory outside of the
intended extraction location.

For Debian 8 "Jessie", this problem has been fixed in version
3.14.1-1+deb8u2.

We recommend that you upgrade your file-roller packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Best,
Utkarsh
- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAl6aQUIACgkQgj6WdgbD
S5aKvg/9HM6jhAKOBpDLhOAfEDjmR+R0ao7BCxArWLJebSBN9A2q9vNjunfGZKyx
KkH2/gBEewaBj6a0iP3rPw0BnEMMVoTljPkQ6a0ZVnAIcxJYFFEy8lAVctshNMG+
gdCO2rmuWnj7x5at5HR8HwnhitLQNKUbbPnA/p2VKK20/f8YHRiF40v+RB7cszvP
/MXUgKR3Wfw/VJBgeHFPxaTS1GGndrHMGhay7Cn5R2gjL4a25Z79GB9TJl50O/54
7yXgLcznLspNAsoZxwUwdq9Xi3tRBV52hyXTmiybC0ZgjNBaIxAWjJPE6/q1INFF
qVGIN3tCGtK//egK3t2kDnAZPGy306xTk4fGC4ZslKjCzvIdi+keCj1/lDSeQ66O
GOmaj3Ojb+3Yx7JR0pS77ALWhSl3/1Gp4vFQG6PJ0skHqqT85wesdrMoqR+baZl3
wpHFYKMZ1rxu2fLneJQCWiYEzUaO6zvBiHOImnEWhI0s/VhQrZLU8mcvIMZ2MQ8G
hNqz78tW2FCIYj7GfAs/wyh76jBkNqs92RTsJLXk0kiqR5VmiImHEh8SyZjV9s4t
8NXwj0t6Zuwd7+6kJdI+/tm45yLFvRswPle+ee086qF/9Fvo4WVVTpUfOcqpdPop
d3xHp8zApRikpJVM+ZdOOuP+yyCyIs6jRvbY6S2Vnq1wbuhb2+4=
=kc09
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXpz9ZmaOgq3Tt24GAQi77A/9FP4L7daau0FyCc21NIX3lrQqfW/k0ik+
sVctaE7G5TOGIG0SzM6REQNcuaqiAiReeN3bXAe+i0AR5vHUuKSkbJ6a9vtQzCry
vfo/EYBeWGYgb3PhYOkOeChkvYtSvws2PVuebEeFeUcPiO4Y+MnjDpn7LUmRfSY7
hoD0phoVLOfZMnb+iwNFeG4B1K+6xJK0hOZIwRn3GQw0dhdZ5L0xylcm+iFWlvWb
ZRoCSh4T8efeJT6HFlay1MmHDETSPFq3UJGxg2FFDPmx7mNrJTLDPybEjs4qbr3/
QOdal9NNaDsPia3wzZDukqCmqSgpQJFkuk/zVirKRFes5lKRR/w/nvcsckw4SyBp
Xzr+V/C/rZi1BTnfD/P63xinus/kSFQv1DpRq0LQW8uEylaUozdeQ2AYuqR/SgBs
NWHv0ceNohOPXSqSsUAmfEjyuBBUzVQTXxm/ieIHJHPYYNHIe1+yFNnw04KsJhHP
s7kaxliibPuLPiY2GXd0TZIIg4wMb8hnwqprogOrUx7jec+GSHgB8vRlaA3Frq13
FJxzgkn56mUnmIXvK2U695hdE87+dMvmvNpe0Sy5azUWT8vAzIrM5MPO2Tf5kZ5M
HCt8bBaDi7obo2D4e6e+Q4C7A8vhD5xb5fY92P+OelpLb6g4rNVasLJzZeiDp4ma
3ulyS7uK2X8=
=+/pd
-----END PGP SIGNATURE-----