CVE-2011-2725
published 2014-02-04CVE-2011-2725: Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot)…
PriorityP335medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.95%
85.6th percentile
Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| kde | ark | <= 2.17 | — |
| kde | kde_sc | <= 4.7.4 | — |
| kde | kde_sc | — | — |
| kde | kde_sc | — | — |
| kde | kde_sc | — | — |
| kde | kde_sc | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
KDE Utilities vulnerability
vendor_ubuntu·2011-11-21
CVE-2011-2725 KDE Utilities vulnerability
Title: KDE Utilities vulnerability
Summary: Ark could be made to remove files.
Tim Brown discovered that Ark did not properly perform input validation
when previewing archive files. If a user were tricked into opening a
crafted archive file, an attacker could remove files via directory
traversal.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
NOTE: In order to build KDE Utilities on Ubuntu 10.04 LTS, 10.10 and 11.04, it
was necessary to rebuild portions of the KDE point release updates.
Red Hat
kdeutils: Ark path traversal
vendor_redhat·2011-07-25·CVSS 6.8
CVE-2011-2725 [MEDIUM] kdeutils: Ark path traversal
kdeutils: Ark path traversal
Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.
Package: kdeutils (Red Hat Enterprise Linux 4) - Will not fix
Package: kdeutils (Red Hat Enterprise Linux 5) - Will not fix
Package: kdeutils (Red Hat Enterprise Linux 6) - Will not fix
GHSA
GHSA-39q3-w6r4-xp9g: Directory traversal vulnerability in Ark 4
ghsa_unreviewed·2022-05-14
CVE-2011-2725 [MEDIUM] CWE-22 GHSA-39q3-w6r4-xp9g: Directory traversal vulnerability in Ark 4
Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2011-2725 KDE Utilities Ark path traversal [fedora-all]
bugzilla·2011-10-07·CVSS 6.8
CVE-2011-2725 [MEDIUM] CVE-2011-2725 KDE Utilities Ark path traversal [fedora-all]
CVE-2011-2725 KDE Utilities Ark path traversal [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=725764
Please note: this issue affects multiple supported vers
Bugzilla
CVE-2011-2725 kdeutils: Ark path traversal
bugzilla·2011-07-26·CVSS 6.8
CVE-2011-2725 [MEDIUM] CVE-2011-2725 kdeutils: Ark path traversal
CVE-2011-2725 kdeutils: Ark path traversal
A path traversal flaw was found in the way Ark, the tool for managing various archive formats within the KDE environment, processed certain Zip archives. A remote attacker could provide a specially-crafted Zip archive, which once opened in the Ark GUI frontend would lead to arbitrary file being opened or, potentially, if the local victim provided correct user credentials could allow that file to be removed.
References:
[1] http://www.openwall.com/lists/oss-security/2011/07/25/9
[2] https://bugzilla.novell.com/show_bug.cgi?id=708268
Discussion:
Further issue details from Nth Dimension Security Advisory (NDSA20110726):
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Nth Dimension Security Advisory (NDSA20110726)
Date: 26th July 2011
Author: Ti
http://lists.opensuse.org/opensuse-updates/2012-03/msg00002.htmlhttp://packetstormsecurity.com/files/105610/Ark-2.16-Directory-Traversal.htmlhttp://seclists.org/fulldisclosure/2011/Oct/351http://www.ubuntu.com/usn/USN-1276-1https://bugzilla.novell.com/show_bug.cgi?id=708268https://bugzilla.redhat.com/show_bug.cgi?id=725764http://lists.opensuse.org/opensuse-updates/2012-03/msg00002.htmlhttp://packetstormsecurity.com/files/105610/Ark-2.16-Directory-Traversal.htmlhttp://seclists.org/fulldisclosure/2011/Oct/351http://www.ubuntu.com/usn/USN-1276-1https://bugzilla.novell.com/show_bug.cgi?id=708268https://bugzilla.redhat.com/show_bug.cgi?id=725764
2014-02-04
Published