Ubuntu has issued an advisory on February 11: https://ubuntu.com/security/notices/USN-4733-1 Mageia 7 and Mageia 8 are also affected.
Status comment: (none) => Patch available from upstream and UbuntuWhiteboard: (none) => MGA8TOO
Done for cauldron, mga8 and mga7!
CC: (none) => geiger.david68210
Fabulous. So please excuse assigning it to you.
Assignee: bugsquad => geiger.david68210
Package list: libgnome-autoar0_0-0.2.3-2.1.mga7 libgnome-autoar-gir0.1-0.2.3-2.1.mga7 libgnome-autoar-devel-0.2.3-2.1.mga7 libgnome-autoar0_0-0.2.4-2.1.mga8 libgnome-autoar-gir0.1-0.2.4-2.1.mga8 libgnome-autoar-devel-0.2.4-2.1.mga8 from SRPMS: gnome-autoar-0.2.3-2.1.mga7.src.rpm gnome-autoar-0.2.4-2.1.mga8.src.rpm
Whiteboard: MGA8TOO => MGA7TOOVersion: Cauldron => 8Status comment: Patch available from upstream and Ubuntu => (none)Assignee: geiger.david68210 => qa-bugs
The following 2 packages are going to be installed: - lib64gnome-autoar-gir0.1-0.2.3-2.1.mga7.x86_64 - lib64gnome-autoar0_0-0.2.3-2.1.mga7.x86_64 worked with transferring file via gnome's file manager. No issues. Well, at least it doesn't seem to break anything at least.
CC: (none) => brtians1Whiteboard: MGA7TOO => MGA7TOO MGA7-64-OK
(In reply to Brian Rockwell from comment #4) > The following 2 packages are going to be installed: > > - lib64gnome-autoar-gir0.1-0.2.3-2.1.mga7.x86_64 > - lib64gnome-autoar0_0-0.2.3-2.1.mga7.x86_64 > > > worked with transferring file via gnome's file manager. No issues. > > Well, at least it doesn't seem to break anything at least. forgot to note: this is a gnome DE system I am testig on.
gnome - mga8 - The following 2 packages are going to be installed: - lib64gnome-autoar-gir0.1-0.2.4-2.1.mga8.x86_64 - lib64gnome-autoar0_0-0.2.4-2.1.mga8.x86_64 --- rebooted --- file transfers done. Nothing appears to be broken.
Whiteboard: MGA7TOO MGA7-64-OK => MGA7TOO MGA7-64-OK MGA8-64-OK
Let's go with it, Brian. Validating.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
Advisory: ======================== Updated gnome-autoar packages fix security vulnerability: Yiğit Can Yılmaz discovered that GNOME Autoar could extract files outside of the intended directory. If a user were tricked into extracting a specially crafted archive, a remote attacker could create files in arbitrary locations, possibly leading to code execution (CVE-2020-36241). References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-36241 https://ubuntu.com/security/notices/USN-4733-1
Advisory pushed to SVN.
CVE: (none) => CVE-2020-36241Keywords: (none) => advisoryCC: (none) => ouaurelien
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2021-0111.html
Resolution: (none) => FIXEDStatus: NEW => RESOLVED