First published: Tue Jul 26 2016(Updated: )
Andreas Cord-Landwehr discovered that KDE-Libs incorrectly handled extracting certain archives. If a user were tricked into extracting a specially-crafted archive, a remote attacker could use this issue to overwrite arbitrary files out of the extraction directory.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libkdecore5 | <4:4.14.13-0ubuntu1.1 | 4:4.14.13-0ubuntu1.1 |
Ubuntu Ubuntu | =15.10 | |
All of | ||
ubuntu/libkdecore5 | <4:4.13.3-0ubuntu0.3 | 4:4.13.3-0ubuntu0.3 |
Ubuntu Ubuntu | =14.04 | |
All of | ||
ubuntu/libkdecore5 | <4:4.8.5-0ubuntu0.5 | 4:4.8.5-0ubuntu0.5 |
Ubuntu Ubuntu | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this advisory is USN-3042-1.
The title of this advisory is USN-3042-1: KDE-Libs vulnerability.
The vulnerability allows a remote attacker to overwrite arbitrary files by tricking a user into extracting a specially-crafted archive.
The software affected by this vulnerability is libkdecore5 version 4:4.14.13-0ubuntu1.1 on Ubuntu 15.10, libkdecore5 version 4:4.13.3-0ubuntu0.3 on Ubuntu 14.04, and libkdecore5 version 4:4.8.5-0ubuntu0.5 on Ubuntu 12.04.
The reference for this vulnerability is 'https://ubuntu.com/security/CVE-2016-6232' and 'https://ubuntu.com/security/notices/USN-4100-1'.