{"id":"MGASA-2013-0232","summary":"Updated file-roller package fixes CVE-2013-4668","details":"Updated file-roller package fixes security vulnerability:\n\nDirectory traversal vulnerability in File Roller 3.6.x before 3.6.4 when\nlibarchive is used, allows remote attackers to create arbitrary files via a\ncrafted archive that is not properly handled in a \"Keep directory structure\"\naction, related to fr-archive-libarchive.c and fr-window.c (CVE-2013-4668).\n","modified":"2026-04-16T04:44:13.848042128Z","published":"2013-07-26T11:39:58Z","upstream":["CVE-2013-4668"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2013-0232.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2013-July/111666.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=10782"}],"affected":[{"package":{"name":"file-roller","ecosystem":"Mageia:3","purl":"pkg:rpm/mageia/file-roller?arch=source&distro=mageia-3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.6.4-1.mga3"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2013-0232.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}