ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications.
libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
A path traversal flaw was found in the way Ark, the tool for managing various archive formats within the KDE environment, processed certain Zip archives. A remote attacker could provide a specially-crafted Zip archive, which once opened in the Ark GUI frontend would lead to arbitrary file being opened or, potentially, if the local victim provided correct user credentials could allow that file to be removed.
References: [1] http://www.openwall.com/lists/oss-security/2011/07/25/9 [2] https://bugzilla.novell.com/showbug.cgi?id=708268
A path traversal flaw was found in the way Ark, the tool for managing various archive formats within the KDE environment, processed certain Zip archives. A remote attacker could provide a specially-crafted Zip archive, which once opened in the Ark GUI frontend would lead to arbitrary file being opened or, potentially, if the local victim provided correct user credentials could allow that file to be removed.
References: [1] http://www.openwall.com/lists/oss-security/2011/07/25/9 [2] https://bugzilla.novell.com/showbug.cgi?id=708268