UNIX symbolic link following in ark - CVE-2020-24654
Published: August 27, 2020
Vulnerability identifier: #VU46109
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-24654
CWE-ID: CWE-61
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a symlink following issue when processing .tar archives in KDE ark. remote attacker can trick the victim to open a specially crafted .tar archive and overwrite arbitrary files on the target system.
Affected software
ark
Gentoo Linux
Arch Linux
Fedora
SUSE Linux
Opensuse
Ubuntu
ark (Debian package)
ark (Alpine package)
akonadi-calendar-tools (Alpine package)
ark (Ubuntu package)
ark
Gentoo Linux
Arch Linux
Fedora
SUSE Linux
Opensuse
Ubuntu
ark (Debian package)
ark (Alpine package)
akonadi-calendar-tools (Alpine package)
ark (Ubuntu package)
ark
How to mitigate CVE-2020-24654
Install updates from vendor's website.
ark - update to 20.08.0
ark (Debian package) - update to 18.08.3-1+deb10u2
ark (Alpine package) - update to 20.08.0-r1
akonadi-calendar-tools (Alpine package) - update to 20.08.1-r0
ark (Ubuntu package) - addressed in versions 4:15.12.3-0ubuntu1.2, 4:17.12.3-0ubuntu1.2, 4:19.12.3-0ubuntu1.2
ark - addressed in versions 19.12.2-3.el8, 20.04.3-5.fc32, 20.04.3-5.fc33
ark (Debian package) - update to 18.08.3-1+deb10u2
ark (Alpine package) - update to 20.08.0-r1
akonadi-calendar-tools (Alpine package) - update to 20.08.1-r0
ark (Ubuntu package) - addressed in versions 4:15.12.3-0ubuntu1.2, 4:17.12.3-0ubuntu1.2, 4:19.12.3-0ubuntu1.2
ark - addressed in versions 19.12.2-3.el8, 20.04.3-5.fc32, 20.04.3-5.fc33
External References
Related Security Bulletins
- Arbitrary file overwrite in KDE Ark
- OpenSUSE Linux update for ark
- UNIX symbolic link following in ark (Alpine package)
- Arch Linux update for ark
- UNIX symbolic link following in akonadi-calendar-tools (Alpine package)
- Debian update for ark
- OpenSUSE Linux update for ark
- Gentoo update for Ark
- Gentoo update for Ark
- Ubuntu update for ark
- Fedora EPEL 8 update for ark
- Fedora 33 update for ark
- Fedora 32 update for ark