USN-4482-1: Ark vulnerability
Published Sep 1, 2020
·Updated
Fabian Vogt discovered that Ark incorrectly handled symbolic links in tar archive files. An attacker could use this to construct a malicious tar archive that, when opened, would create files outside the extraction directory.
Affected Software
0 affected components
Event History
Feb 23, 2026
Advisory Published
via Ubuntu·09:23 PM
Data Sourced
via Ubuntu·09:23 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is USN-4482-1.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Ark vulnerability'.
3
Who discovered the vulnerability?
The vulnerability was discovered by Fabian Vogt.
4
What is the impact of the vulnerability?
The vulnerability allows an attacker to create files outside the extraction directory.
5
How can I fix the vulnerability?
To fix the vulnerability, update the Ark package to version 4:19.12.3-0ubuntu1.2 for Ubuntu 20.04, version 4:17.12.3-0ubuntu1.2 for Ubuntu 18.04, or version 4:15.12.3-0ubuntu1.2 for Ubuntu 16.04.