First published: Mon Aug 03 2020(Updated: )
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/ark | <4:17.12.3-0ubuntu1.1 | 4:17.12.3-0ubuntu1.1 |
ubuntu/ark | <4:19.12.3-0ubuntu1.1 | 4:19.12.3-0ubuntu1.1 |
ubuntu/ark | <4:20.04.3-1 | 4:20.04.3-1 |
debian/ark | 4:18.08.3-1+deb10u2 4:20.12.2-1 4:22.12.3-1 4:23.08.1-2 | |
KDE Ark | <20.08.0 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16116 is a vulnerability in KDE Ark before 20.08.0 that allows a crafted archive to install files outside the extraction directory via directory traversal.
CVE-2020-16116 has a severity level of medium (3.3).
CVE-2020-16116 affects KDE Ark versions 4:17.12.3-0ubuntu1.1, 4:19.12.3-0ubuntu1.1, 4:20.04.3-1, and earlier.
To fix CVE-2020-16116, you can update KDE Ark to version 20.08.0 or later.
You can find more information about CVE-2020-16116 in the following references: [link1], [link2], [link3].