An issue was discovered in GNOME file-roller before 3.29.91. It allows a single ./../ path traversal via a filename contained in a TAR archive, possibly overwriting a file during extraction.
| Software | From | Fixed in |
|---|---|---|
| gnome / file-roller | - | 3.29.91 |
| redhat / enterprise_linux | 7.0 | 7.0.x |
| debian / debian_linux | 8.0 | 8.0.x |
| canonical / ubuntu_linux | 16.04 | 16.04.x |
| debian / debian_linux | 9.0 | 9.0.x |
| canonical / ubuntu_linux | 18.04 | 18.04.x |
| redhat / enterprise_linux | 8.0 | 8.0.x |