Path traversal in ark - CVE-2020-16116
Published: July 30, 2020 / Updated: August 14, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the archive. A remote attacker can create a specially crafted archive, trick the victim into extracting files from it and overwrite arbitrary files on the system with privileges of the current user.
Affected software
Gentoo Linux
Debian Linux
Fedora
SUSE Linux
Opensuse
Ubuntu
ark (Alpine package)
akonadi-calendar-tools (Alpine package)
ark (Ubuntu package)
ark (Debian package)
ark
How to mitigate CVE-2020-16116
ark (Alpine package) - update to 20.04.3-r1
akonadi-calendar-tools (Alpine package) - update to 20.08.0-r0
ark (Ubuntu package) - addressed in versions 4:17.12.3-0ubuntu1.1, 4:19.12.3-0ubuntu1.1
ark (Debian package) - update to 4:18.08.3-1+deb10u1
ark - addressed in versions 19.12.2-2.el8, 20.04.3-3.fc31, 20.04.3-3.fc32
External References
Related Security Bulletins
- Path traversal when extracting archives in KDE Ark
- Gentoo update for Ark
- OpenSUSE Linux update for ark
- Path traversal in akonadi-calendar-tools (Alpine package)
- Path traversal in ark (Alpine package)
- OpenSUSE Linux update for ark
- Debian update for ark
- Ubuntu update for ark
- Fedora 31 update for ark
- Fedora 32 update for ark
- Fedora EPEL 8 update for ark