CVE-2016-6232: Path Traversal
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2016-6232.
What is the title of the vulnerability?
The title of the vulnerability is 'Directory traversal vulnerability in KArchive before 5.24 as used in KDE Frameworks allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.'
What software is affected by this vulnerability?
KArchive before version 5.24, KDE Frameworks, kde4libs, and karchive on various Ubuntu and Debian versions.
What is the severity of CVE-2016-6232?
The severity of CVE-2016-6232 is high with a CVSS score of 7.5.
How can I fix this vulnerability?
To fix this vulnerability, update to a version that includes the fix provided by the vendor.