Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote attackers to create arbitrary files via a crafted archive that is not properly handled in a "Keep directory structure" action, related to fr-archive-libarchive.c and fr-window.c.
| Software | From | Fixed in |
|---|---|---|
| file_roller_project / file_roller | 3.9.1 | 3.9.3 |
| file_roller_project / file_roller | 3.8.0 | 3.8.3 |
| file_roller_project / file_roller | 3.6.0 | 3.6.4 |
| canonical / ubuntu_linux | 13.04 | 13.04.x |
| canonical / ubuntu_linux | 12.10 | 12.10.x |