CVE-2020-16116
Summary
| CVE | CVE-2020-16116 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-03 20:15:00 UTC |
| Updated | 2023-11-07 03:18:00 UTC |
| Description | In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Fix vulnerability to path traversal attacks (0df59252) · Commits · Utilities / Ark · GitLab |
CONFIRM |
invent.kde.org |
Patch, Vendor Advisory |
| [SECURITY] Fedora 31 Update: ark-20.04.3-3.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 32 Update: ark-20.04.3-3.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| USN-4461-1: Ark vulnerability | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
|
| [SECURITY] Fedora 31 Update: ark-20.04.3-3.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [security-announce] openSUSE-SU-2020:1183-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| Ark: Arbitrary code execution (GLSA 202008-03) — Gentoo security |
GENTOO |
security.gentoo.org |
Third Party Advisory |
| kde.org/info/security/advisory-20200730-1.txt |
CONFIRM |
kde.org |
Vendor Advisory |
| [SECURITY] Fedora 32 Update: ark-20.04.3-3.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| Commits · KDE/ark · GitHub |
MISC |
github.com |
Release Notes, Third Party Advisory |
| Debian -- Security Information -- DSA-4738-1 ark |
CONFIRM |
www.debian.org |
Third Party Advisory |
| [SECURITY] [DLA 3015-1] ark security update |
MLIST |
lists.debian.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 179301 Debian Security Update for ark (DLA 3015-1)
- 500839 Alpine Linux Security Update for ark
- 501526 Alpine Linux Security Update for ark
- 504583 Alpine Linux Security Update for ark
- 690463 Free Berkeley Software Distribution (FreeBSD) Security Update for ark (d1ef1138-d273-11ea-a757-e0d55e2a8bf9)