CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.5. See the original NVD description below for full technical details.
CVE
CVE-2021-28650
Severity
MEDIUM
CVSS
5.5
EPSS
0.53%
Original NVD Description
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.
Related CVEs
Other vulnerabilities affecting the same vendor(s)