File Roller is a focused archive-management utility for Linux desktop environments, with its vulnerability exposure concentrated in the file_roller application itself and characterized by input-handling deficiencies such as improper input validation and path-traversal conditions. These weakness classes reflect the parsing demands of decompressing and extracting untrusted archive formats; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by File Roller Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-7162HIGH The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an a | Sep 26, 2016 | 7.5 | 26 | NO | NO |
CVE-2013-4668MEDIUM Directory traversal vulnerability in File Roller 3.6.x before 3.6.4, 3.8.x before 3.8.3, and 3.9.x before 3.9.3, when libarchive is used, allows remote attackers to create arbitrar | Jul 18, 2013 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by File Roller Project.
Media articles that mention a CVE ID that affects a product developed by File Roller Project — matched by CVE ID, not by vendor name.