[ubuntu/trusty-security] file-roller 3.10.2.1-0ubuntu4.2 (Accepted)

Tyler Hicks tyhicks at canonical.com
Thu Sep 8 21:03:56 UTC 2016


file-roller (3.10.2.1-0ubuntu4.2) trusty-security; urgency=medium

  * SECURITY UPDATE: Path traversal flaw allows arbitrary file deletion via
    malicious archive (LP: #1171236)
    - debian/patches/CVE-2016-7162.patch: Do not follow symlinks when deleting
      a folder recursively. Based on upstream patch.
    - CVE-2016-7162

Date: 2016-09-08 14:41:31.523873+00:00
Changed-By: Tyler Hicks <tyhicks at canonical.com>
https://launchpad.net/ubuntu/+source/file-roller/3.10.2.1-0ubuntu4.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Trusty-changes mailing list