UNIX symbolic link following in ark - CVE-2020-24654

 

UNIX symbolic link following in ark - CVE-2020-24654

Published: August 27, 2020


Vulnerability identifier: #VU46109
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-24654
CWE-ID: CWE-61
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a symlink following issue when processing .tar archives in KDE ark.  remote attacker can trick the victim to open a specially crafted .tar archive and overwrite arbitrary files on the target system.


Affected software

ark
Gentoo Linux
Arch Linux
Fedora
SUSE Linux
Opensuse
Ubuntu
ark (Debian package)
ark (Alpine package)
akonadi-calendar-tools (Alpine package)
ark (Ubuntu package)
ark

How to mitigate CVE-2020-24654

Install updates from vendor's website.

ark - update to 20.08.0
ark (Debian package) - update to 18.08.3-1+deb10u2
ark (Alpine package) - update to 20.08.0-r1
akonadi-calendar-tools (Alpine package) - update to 20.08.1-r0
ark (Ubuntu package) - addressed in versions 4:15.12.3-0ubuntu1.2, 4:17.12.3-0ubuntu1.2, 4:19.12.3-0ubuntu1.2
ark - addressed in versions 19.12.2-3.el8, 20.04.3-5.fc32, 20.04.3-5.fc33

External References

Related Security Bulletins