4.3

CVE-2020-24654

In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kde ≫ Ark Version < 20.08.1
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 20.04 SwEdition lts
Debian ≫ Debian Linux Version 10.0
Fedoraproject ≫ Fedora Version 32
Opensuse ≫ Leap Version 15.1
Opensuse ≫ Leap Version 15.2
Debian ≫ Debian Linux Version 9.0
Fedoraproject ≫ Fedora Version 33
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.5% 0.708
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://lists.debian.org/debian-lts-announce/2022/05/msg00026.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00001.html
Third Party Advisory
Mailing List
https://bugzilla.suse.com/show_bug.cgi?id=1175857
Third Party Advisory
Issue Tracking
https://github.com/KDE/ark/commit/8bf8c5ef07b0ac5e914d752681e470dea403a5bd
Patch
Third Party Advisory
https://kde.org/info/security/advisory-20200827-1.txt
Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LXMMXNJDYOCJRZTESIUGHG6CS4RJKECX/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJOZ6YRNPZX5MJGVBMOCOA7N6Z4EU2OK/
https://security.gentoo.org/glsa/202010-06
Third Party Advisory
https://security.gentoo.org/glsa/202101-06
Third Party Advisory
https://usn.ubuntu.com/4482-1/
Third Party Advisory
https://www.debian.org/security/2020/dsa-4759
Third Party Advisory