CVE-2020-11736: Canonical Ubuntu Linux

Low severity, CVSS 3.9. EPSS: 0.8% chance of exploitation in the next 30 days.

fr-archive-libarchive.c in GNOME file-roller through 3.36.1 allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink to a directory outside of the intended extraction location.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only; version 20.04 only
  • Debian Debian Linux: version 8.0 only
  • Gnome File-Roller: up to and including 3.36.1

Published 2020-04-13. Last modified 2026-06-17.