CVE-2020-36314: Fedoraproject Fedora
Low severity, CVSS 3.9. EPSS: 0.6% chance of exploitation in the next 30 days.
fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.
Affected products
- Fedoraproject Fedora: version 34 only
- Gnome File-Roller: up to and including 3.38.0
Published 2021-04-07. Last modified 2026-06-17.