==========================================================================
Ubuntu Security Notice USN-4332-2
April 27, 2020
file-roller vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 20.04 LTS
Summary:
File Roller could be made to expose sensitive information.
Software Description:
– file-roller: archive manager for GNOME
Details:
USN-4332-1 fixed vulnerabilities in File Roller. This update provides
the corresponding update for Ubuntu 20.04 LTS.
Original advisory details:
It was discovered that File Roller incorrectly handled symlinks.
An attacker could possibly use this issue to expose sensitive information.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 20.04 LTS:
file-roller 3.36.1-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References:
https://usn.ubuntu.com/4332-2
https://usn.ubuntu.com/4332-1
CVE-2020-11736
Package Information:
https://launchpad.net/ubuntu/+source/file-roller/3.36.1-1ubuntu0.1
—–BEGIN PGP SIGNATURE—–
iQIzBAABCgAdFiEEf+ebRFcoyOoAQoOeRbznW4QLH2kFAl6nN8MACgkQRbznW4QL
H2nojxAAjxqGLn0b6dccHCdJ7FzUazQRkcBBppIIHV+rOmXPYsAPrvFSUek/QIO/
7qGcIqZKMJJlh2M0GYSpeSQqmKoApp/ctaGYBdDKLI565+Ry8ksi96F2db1kxQxq
oYEes7QwMOpKZ5MzcuppYsttjtpsOSVIoF0OiJcX2cy22+0WQtf+M687UpAkAF1r
C8WKP92qSWs715zKhyjNkz3O3Z9FMGwUjfMiB+D5Th5RYxeMIfWx+pR36SIrq2qs
M2eRD3NT5Xd95hibof6hWzLnZxlbKR8oavh4HhDwuje+leeog3vRDwyxU9vncT8u
5ml4MbiIRKQu6ggT9e5RnD/5NhwYn9RpTwx+U+VD9if1t1uNFMbgBWUIBksrYu74
QSaW6AcpFlkiv5EqTcmsjVLvdGeaCnRdavY01aWkC3+yv1lAwxrRhnNVStKRm/dW
GNQc1KwhyDshJWkMLR/jaTcqtCRd5V8u8ZL09UpGwLmCRRcfzHzo3kYvek+3nmEi
dGV527Rhc+ZrABSTm/Y+WSUaUav5v770gZI39WgSnbkKUZdLK6oqYgqAZoQ5FRMw
rPs73KbrKJC/vTj7IfDrU0KVWHmPUH4q9ZCWPB6tW7GKVO7XEH+EwD9ztuPhYIQn
anTj7HT9TT/lXMSMSe09R/DbQf2wYkfJad3djD+OCoU7hb+EZ6s=
=sNEg
—–END PGP SIGNATURE—–
—