CVE-2016-6232

Published on: 08/02/2016 12:00:00 AM UTC

Last Modified on: 03/23/2021 11:27:11 PM UTC

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Certain versions of Ubuntu Linux from Canonical contain the following vulnerability:

Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.

  • CVE-2016-6232 has been assigned by URL Logo [email protected] to track the vulnerability - currently rated as HIGH severity.

CVSS3 Score: 7.5 - HIGH

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK LOW NONE NONE
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED NONE HIGH NONE

CVSS2 Score: 5 - MEDIUM

Access
Vector
Access
Complexity
Authentication
NETWORK LOW NONE
Confidentiality
Impact
Integrity
Impact
Availability
Impact
NONE PARTIAL NONE

CVE References

Description Tags Link
oss-security - Re: CVE Request for KNewStuff/KArchive issue Third Party Advisory
www.openwall.com
text/html
URL Logo MLIST [oss-security] 20160716 Re: CVE Request for KNewStuff/KArchive issue
Debian -- Security Information -- DSA-3643-1 kde4libs www.debian.org
Depreciated Link
text/html
URL Logo DEBIAN DSA-3643
KDE KArchive CVE-2016-6232 Security Bypass Vulnerability cve.report (archive)
text/html
URL Logo BID 91806
[security-announce] openSUSE-SU-2016:2223-1: important: Security update lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:2223
USN-3042-1: KDE-Libs vulnerability | Ubuntu Patch
www.ubuntu.com
text/html
URL Logo UBUNTU USN-3042-1
oss-security - CVE Request for KNewStuff/KArchive issue www.openwall.com
text/html
URL Logo MLIST [oss-security] 20160716 CVE Request for KNewStuff/KArchive issue
USN-4100-1: KConfig and KDE libraries vulnerabilities | Ubuntu security notices | Ubuntu usn.ubuntu.com
text/html
URL Logo UBUNTU USN-4100-1
Git repository browser web.archive.org
text/html
Inactive LinkNot Archived
URL Logo CONFIRM quickgit.kde.org/?p=karchive.git&a=commit&h=0cb243f64eef45565741b27364cece7d5c349c37
Exploit
Mitigation
Vendor Advisory
www.kde.org
text/plain
URL Logo CONFIRM www.kde.org/info/security/advisory-20160724-1.txt
[security-announce] openSUSE-SU-2016:1884-1: important: Security update lists.opensuse.org
text/html
URL Logo SUSE openSUSE-SU-2016:1884

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
Operating
System
CanonicalUbuntu Linux12.04AllAllAll
Operating
System
CanonicalUbuntu Linux14.04AllAllAll
Operating
System
CanonicalUbuntu Linux15.10AllAllAll
Operating
System
CanonicalUbuntu Linux12.04AllAllAll
Operating
System
CanonicalUbuntu Linux14.04AllAllAll
Operating
System
CanonicalUbuntu Linux15.10AllAllAll
ApplicationKdeKarchivesAllAllAllAll
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*:
  • cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*:
  • cpe:2.3:a:kde:karchives:*:*:*:*:*:*:*:*: