First published: Tue Sep 01 2020(Updated: )
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
KDE Ark | <20.08.1 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =18.04 | |
Canonical Ubuntu Linux | =20.04 | |
Debian Debian Linux | =10.0 | |
Fedoraproject Fedora | =32 | |
openSUSE Leap | =15.1 | |
openSUSE Leap | =15.2 | |
Debian Debian Linux | =9.0 | |
Fedoraproject Fedora | =33 | |
debian/ark | <=4:20.08.0-1<=4:18.08.3-1+deb10u1<=4:18.08.3-1 | 4:20.08.1-1 4:18.08.3-1+deb10u2 |
ubuntu/ark | <4:17.12.3-0ubuntu1.2 | 4:17.12.3-0ubuntu1.2 |
ubuntu/ark | <4:19.12.3-0ubuntu1.2 | 4:19.12.3-0ubuntu1.2 |
ubuntu/ark | <4:15.12.3-0ubuntu1.2 | 4:15.12.3-0ubuntu1.2 |
debian/ark | 4:20.12.2-1 4:22.12.3-1 4:23.08.5-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this CVE is CVE-2020-24654.
The severity of CVE-2020-24654 is high with a severity value of 3.3.
The affected software of CVE-2020-24654 includes KDE Ark versions before 20.08.1.
CVE-2020-24654 can be exploited by using a crafted TAR archive with symlinks to install files outside the extraction directory.
Yes, there are remedies available for CVE-2020-24654. For Debian, the remedy versions are 4:20.08.1-1 and 4:18.08.3-1+deb10u2.