ALT-PU-2022-4505-1
Package kde5-ark updated to version 21.12.3-alt1 for branch sisyphus_e2k.
Closed vulnerabilities
BDU:2021-01751
Уязвимость функции emitEntryFromArchiveEntry из libarchiveplugin.cpp архиватора Ark, связанная с неверным определением ссылки перед доступом к файлу, позволяющая нарушителю оказать воздействие на целостность данных
BDU:2021-03629
Уязвимость функции Job::onEntry из jobs.cpp архиватора Ark, связанная с недостатками ограничения имени пути к каталогу, позволяющая нарушителю оказать воздействие на целостность защищаемой информации
Modified: 2024-11-21
CVE-2020-16116
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
- openSUSE-SU-2020:1183
- openSUSE-SU-2020:1183
- https://github.com/KDE/ark/commits/master
- https://github.com/KDE/ark/commits/master
- https://invent.kde.org/utilities/ark/-/commit/0df592524fed305d6fbe74ddf8a196bc9ffdb92f
- https://invent.kde.org/utilities/ark/-/commit/0df592524fed305d6fbe74ddf8a196bc9ffdb92f
- https://kde.org/info/security/advisory-20200730-1.txt
- https://kde.org/info/security/advisory-20200730-1.txt
- [debian-lts-announce] 20220520 [SECURITY] [DLA 3015-1] ark security update
- [debian-lts-announce] 20220520 [SECURITY] [DLA 3015-1] ark security update
- FEDORA-2020-e2fe8f0165
- FEDORA-2020-e2fe8f0165
- FEDORA-2020-cac5ae9b6e
- FEDORA-2020-cac5ae9b6e
- GLSA-202008-03
- GLSA-202008-03
- USN-4461-1
- USN-4461-1
- https://www.debian.org/security/2020/dsa-4738
- https://www.debian.org/security/2020/dsa-4738
Modified: 2024-11-21
CVE-2020-24654
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
- openSUSE-SU-2020:1310
- openSUSE-SU-2020:1310
- https://bugzilla.suse.com/show_bug.cgi?id=1175857
- https://bugzilla.suse.com/show_bug.cgi?id=1175857
- https://github.com/KDE/ark/commit/8bf8c5ef07b0ac5e914d752681e470dea403a5bd
- https://github.com/KDE/ark/commit/8bf8c5ef07b0ac5e914d752681e470dea403a5bd
- https://kde.org/info/security/advisory-20200827-1.txt
- https://kde.org/info/security/advisory-20200827-1.txt
- [debian-lts-announce] 20220520 [SECURITY] [DLA 3015-1] ark security update
- [debian-lts-announce] 20220520 [SECURITY] [DLA 3015-1] ark security update
- FEDORA-2020-c2f8a1e8a5
- FEDORA-2020-c2f8a1e8a5
- FEDORA-2020-f04f41bcc9
- FEDORA-2020-f04f41bcc9
- GLSA-202010-06
- GLSA-202010-06
- GLSA-202101-06
- GLSA-202101-06
- USN-4482-1
- USN-4482-1
- DSA-4759
- DSA-4759