Path traversal in ark - CVE-2020-16116

 

Path traversal in ark - CVE-2020-16116

Published: July 30, 2020 / Updated: August 14, 2020


Vulnerability identifier: #VU32924
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-16116
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences within the archive. A remote attacker can create a specially crafted archive, trick the victim into extracting files from it and overwrite arbitrary files on the system with privileges of the current user.


Affected software

ark
Gentoo Linux
Debian Linux
Fedora
SUSE Linux
Opensuse
Ubuntu
ark (Alpine package)
akonadi-calendar-tools (Alpine package)
ark (Ubuntu package)
ark (Debian package)
ark

How to mitigate CVE-2020-16116

Install updates from vendor's website.

ark - update to 20.08.0
ark (Alpine package) - update to 20.04.3-r1
akonadi-calendar-tools (Alpine package) - update to 20.08.0-r0
ark (Ubuntu package) - addressed in versions 4:17.12.3-0ubuntu1.1, 4:19.12.3-0ubuntu1.1
ark (Debian package) - update to 4:18.08.3-1+deb10u1
ark - addressed in versions 19.12.2-2.el8, 20.04.3-3.fc31, 20.04.3-3.fc32

External References

Related Security Bulletins