[ubuntu/trusty-updates] file-roller 3.10.2.1-0ubuntu4.2 (Accepted)

Ubuntu Archive Robot cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk
Thu Sep 8 21:58:17 UTC 2016


file-roller (3.10.2.1-0ubuntu4.2) trusty-security; urgency=medium

  * SECURITY UPDATE: Path traversal flaw allows arbitrary file deletion via
    malicious archive (LP: #1171236)
    - debian/patches/CVE-2016-7162.patch: Do not follow symlinks when deleting
      a folder recursively. Based on upstream patch.
    - CVE-2016-7162

Date: 2016-09-08 14:41:31.523873+00:00
Changed-By: Tyler Hicks <tyhicks at canonical.com>
Signed-By: Ubuntu Archive Robot <cjwatson+ubuntu-archive-robot at chiark.greenend.org.uk>
https://launchpad.net/ubuntu/+source/file-roller/3.10.2.1-0ubuntu4.2
-------------- next part --------------
Sorry, changesfile not available.


More information about the Trusty-changes mailing list