GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://gitlab.gnome.org/GNOME/nautilus/-/tree/master | product |
https://gitlab.gnome.org/GNOME/nautilus/-/issues/2376 | patch third party advisory issue tracking exploit |
https://gitlab.gnome.org/GNOME/nautilus/-/merge_requests/1001 | patch |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PX5CVF4FAHFA6UNKHFBBLOP2NUMIQJAY/ | vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XYPDZ7LBBUVU3WFK7DCGDFGK2GXTKGT5/ | vendor advisory |