3.3
CVSSv3

CVE-2020-16116

Published: 03/08/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 3.3 | Impact Score: 1.4 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

In kerfuffle/jobs.cpp in KDE Ark prior to 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

kde ark

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 31

fedoraproject fedora 32

opensuse leap 15.1

opensuse leap 15.2

canonical ubuntu linux 18.04

canonical ubuntu linux 20.04

Vendor Advisories

Dominik Penner discovered that the Ark archive manager did not sanitise extraction paths, which could result in maliciously crafted archives writing outside the extraction directory For the stable distribution (buster), this problem has been fixed in version 4:18083-1+deb10u1 We recommend that you upgrade your ark packages For the detailed sec ...

Recent Articles

Oh cool, more Cisco patches to apply. Happy Monday
The Register • Shaun Nichols in San Francisco • 03 Aug 2020

Meanwhile, KDE desktops can be pwned by evil archives

In Brief Cisco customers once again find themselves needing to patch critical vulnerabilities in Switchzilla's gear. The equipment maker has emitted fixes or updates for multiple CVE-listed vulnerabilities in the Treck IP stack (the Ripple20 bugs), Data Center Network Manager, and SD-WAN. Those patches should be applied ASAP. A high-rated path traversal vulnerability was patched in the Adaptive Security Appliance and Firepower Threat Defense software. Additionally, there were five high-rated bul...