{"id":"CVE-2016-7162","details":"The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.","modified":"2026-07-08T05:50:07.214300284Z","published":"2016-09-26T15:59:04.343Z","database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"canonical:ubuntu_linux","cpes":["cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*","cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"],"extracted_events":[{"introduced":"14.04"},{"last_affected":"14.04"},{"introduced":"16.04"},{"last_affected":"16.04"}]},{"cpes":["cpe:2.3:a:file_roller_project:file_roller:3.15:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.9.0:*:*:*:*:gnome:*:*"],"extracted_events":[{"introduced":"3.9.0"},{"last_affected":"3.9.0"},{"introduced":"3.15"},{"last_affected":"3.15"}],"source":"CPE_STRING","vendor_product":"file_roller_project:file_roller"}]},"references":[{"type":"WEB","url":"http://ftp.gnome.org/mirror/gnome.org/sources/file-roller/3.21/file-roller-3.21.90.news"},{"type":"ADVISORY","url":"http://ftp.gnome.org/mirror/gnome.org/sources/file-roller/3.20/file-roller-3.20.3.news"},{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/09/08/4"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/92896"},{"type":"ADVISORY","url":"http://www.ubuntu.com/usn/USN-3074-1"},{"type":"REPORT","url":"https://bugzilla.gnome.org/show_bug.cgi?id=698554"},{"type":"FIX","url":"https://git.gnome.org/browse/file-roller/commit/?id=f70be1f41688859ec8dbe266df35a1839ceb96c5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.gnome.org/gnome/file-roller","events":[{"introduced":"7850fc12a13e9f33e09d511014488358bfffbdb9"},{"last_affected":"440695f1a684cdb01837c66d5f7f3b1dcad4f5b3"}],"database_specific":{"cpe":["cpe:2.3:a:file_roller_project:file_roller:3.5.4:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.6.0:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.6.1:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.6.1.1:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.6.2:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.6.3:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.6.4:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.8.0:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.8.1:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.8.2:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.8.3:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.9.1:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.9.2:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.9.3:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.10:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.20:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.20.1:*:*:*:*:gnome:*:*","cpe:2.3:a:file_roller_project:file_roller:3.20.2:*:*:*:*:gnome:*:*"],"extracted_events":[{"introduced":"3.5.4"},{"last_affected":"3.5.4"},{"introduced":"3.6.0"},{"last_affected":"3.6.0"},{"introduced":"3.6.1"},{"last_affected":"3.6.1"},{"introduced":"3.6.1.1"},{"last_affected":"3.6.1.1"},{"introduced":"3.6.2"},{"last_affected":"3.6.2"},{"introduced":"3.6.3"},{"last_affected":"3.6.3"},{"introduced":"3.6.4"},{"last_affected":"3.6.4"},{"introduced":"3.8.0"},{"last_affected":"3.8.0"},{"introduced":"3.8.1"},{"last_affected":"3.8.1"},{"introduced":"3.8.2"},{"last_affected":"3.8.2"},{"introduced":"3.8.3"},{"last_affected":"3.8.3"},{"introduced":"3.9.1"},{"last_affected":"3.9.1"},{"introduced":"3.9.2"},{"last_affected":"3.9.2"},{"introduced":"3.9.3"},{"last_affected":"3.9.3"},{"introduced":"3.10"},{"last_affected":"3.10"},{"introduced":"3.20"},{"last_affected":"3.20"},{"introduced":"3.20.1"},{"last_affected":"3.20.1"},{"introduced":"3.20.2"},{"last_affected":"3.20.2"}],"source":"CPE_STRING"}}],"versions":["3.10","3.20","3.20.1","3.20.2","3.5.4","3.6.0","3.6.1","3.6.1.1","3.6.2","3.6.3","3.6.4","3.8.0","3.8.1","3.8.2","3.8.3","3.9.1","3.9.2","3.9.3","3.20.0","3.19.91","3.19.90","3.19.1","3.16.4","3.16.3","3.16.2","3.16.1","3.16.0","3.15.92","3.15.91","3.15.90","3.15.2","3.14.1","3.15.1","3.14.0","3.13.92","3.13.91","3.13.2","3.13.1","3.12.1","3.12.0","3.11.92","3.11.91","3.11.90","3.11.5","3.11.4","3.11.3","3.11.2","3.11.1","3.10.1","3.10.0","3.9.92","3.9.91","3.9.90","3.9.4","3.7.92","3.7.91","3.7.90","3.7.3","3.7.2","3.7.1","3.5.92","3.5.91","3.5.90"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-7162.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}