CVE-2020-16116: Path Traversal
Published Aug 3, 2020
·Updated
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
Affected Software
10 affected componentsFixes available
KDE Ark<20.08.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Fedoraproject Fedora=31
Fedoraproject Fedora=32
openSUSE Leap=15.1
openSUSE Leap=15.2
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
debian/ark
4:20.12.2-14:20.12.2-1+deb11u14:22.12.3-1+deb12u14:25.04.3-14:25.12.1-1
Remediation
Patch Available
Event History
Aug 3, 2020
CVE Published
via MITRE·07:34 PM
Data Sourced
via MITRE·07:34 PM
Description
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 23, 2026
Data Sourced
via Ubuntu·08:04 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·08:05 PM
Description
Data Sourced
via Debian·08:05 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2020-16116?
CVE-2020-16116 is a vulnerability in KDE Ark before 20.08.0 that allows a crafted archive to install files outside the extraction directory via directory traversal.
2
How severe is CVE-2020-16116?
CVE-2020-16116 has a severity level of medium (3.3).
3
What software is affected by CVE-2020-16116?
CVE-2020-16116 affects KDE Ark versions 4:17.12.3-0ubuntu1.1, 4:19.12.3-0ubuntu1.1, 4:20.04.3-1, and earlier.
4
How can I fix CVE-2020-16116?
To fix CVE-2020-16116, you can update KDE Ark to version 20.08.0 or later.
5
Where can I find more information about CVE-2020-16116?
You can find more information about CVE-2020-16116 in the following references: [link1], [link2], [link3].