CVE-2024-57966: Medium severity kde ark vulnerability
Published Feb 3, 2025
·Updated
libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.
Affected Software
1 affected component
KDE Ark<24.12.0
Event History
Feb 3, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-57966?
CVE-2024-57966 has been classified as a high severity vulnerability.
2
How do I fix CVE-2024-57966?
To fix CVE-2024-57966, upgrade KDE Ark to version 24.12.0 or later.
3
What type of vulnerability is CVE-2024-57966?
CVE-2024-57966 is a path traversal vulnerability that allows extraction of files to absolute paths.
4
Which versions of KDE Ark are affected by CVE-2024-57966?
KDE Ark versions before 24.12.0 are affected by CVE-2024-57966.
5
What impact does CVE-2024-57966 have on system security?
CVE-2024-57966 can lead to unauthorized file extraction and potential overwriting of critical system files.