4.3
CVSSv2

CVE-2018-1000801

Published: 06/09/2018 Updated: 20/03/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

okular version 18.08 and previous versions contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be exploitable via he victim must open a specially crafted Okular archive. This issue appears to have been corrected in version 18.08.1

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kde okular

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Synopsis Moderate: okular security update Type/Severity Security Advisory: Moderate Topic An update for okular is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base score, whic ...
Debian Bug report logs - #908168 okular: CVE-2018-1000801 Package: src:okular; Maintainer for src:okular is Debian Qt/KDE Maintainers <debian-qt-kde@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 6 Sep 2018 21:18:01 UTC Owned by: Simon Quigley <tsimonq2@ubuntucom> Severity: ...
A path traversal vulnerability has been discovered in Okular, in the way it creates temporary files when reading an Okular archive Paths are read from contentxml and they are not properly sanitized before being used as template file names for the temporary files created when extracting the Okular archive, thus allowing a local attacker to write f ...