CVE-2020-24654: Medium severity KDE Ark vulnerability
Published Sep 2, 2020
·Updated
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
Affected Software
12 affected componentsFixes available
debian/ark<=4:20.08.0-1, <=4:18.08.3-1+deb10u1, <=4:18.08.3-1
4:20.08.1-14:18.08.3-1+deb10u2
KDE Ark<20.08.1
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=20.04
Debian Debian Linux=10.0
Fedoraproject Fedora=32
openSUSE Leap=15.1
openSUSE Leap=15.2
Debian Debian Linux=9.0
Fedoraproject Fedora=33
debian/ark
4:20.12.2-14:20.12.2-1+deb11u14:22.12.3-1+deb12u14:25.04.3-14:25.12.1-1
Remediation
Event History
Sep 2, 2020
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
Description
Data Sourced
via NVD·05:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 23, 2026
Data Sourced
via Ubuntu·09:23 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·09:24 PM
DescriptionAffected Software
Data Sourced
via Launchpad·09:24 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this CVE?
The vulnerability ID of this CVE is CVE-2020-24654.
2
What is the severity of CVE-2020-24654?
The severity of CVE-2020-24654 is high with a severity value of 3.3.
3
What is the affected software of CVE-2020-24654?
The affected software of CVE-2020-24654 includes KDE Ark versions before 20.08.1.
4
How can CVE-2020-24654 be exploited?
CVE-2020-24654 can be exploited by using a crafted TAR archive with symlinks to install files outside the extraction directory.
5
Are there any remedies available for CVE-2020-24654?
Yes, there are remedies available for CVE-2020-24654. For Debian, the remedy versions are 4:20.08.1-1 and 4:18.08.3-1+deb10u2.