CVE-2016-6232
published 2016-08-02CVE-2016-6232: Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot…
PriorityP347high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
4.43%
90.3th percentile
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | karchive | < karchive 5.24.0-1 (bookworm) | karchive 5.24.0-1 (bookworm) |
| kde | karchives | <= 5.24 | — |
| kde | kconfig | >= 0 < 5.18.0-0ubuntu1.1 | 5.18.0-0ubuntu1.1 |
| kde | kconfig | >= 0 < 5.44.0-0ubuntu1.1 | 5.44.0-0ubuntu1.1 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
KConfig and KDE libraries vulnerabilities
vendor_ubuntu·2019-08-16·CVSS 7.5
CVE-2016-6232 [HIGH] KConfig and KDE libraries vulnerabilities
Title: KConfig and KDE libraries vulnerabilities
Summary: KConfig and KDE libraries could be made to crash or run programs if it
opened a specially crafted file.
It was discovered that KConfig and KDE libraries have a vulnerability
where an attacker could hide malicious code under desktop and
configuration files. (CVE-2019-14744)
It was discovered that KConfig allows remote attackers to write to
arbitrary files via a ../ in a filename in an archive file. (CVE-2016-6232)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
KDE-Libs vulnerability
vendor_ubuntu·2016-07-26
CVE-2016-6232 KDE-Libs vulnerability
Title: KDE-Libs vulnerability
Summary: KDE-Libs could be made to overwrite files.
Andreas Cord-Landwehr discovered that KDE-Libs incorrectly handled
extracting certain archives. If a user were tricked into extracting a
specially-crafted archive, a remote attacker could use this issue to
overwrite arbitrary files out of the extraction directory.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Debian
CVE-2016-6232: karchive - Directory traversal vulnerability in KArchive before 5.24, as used in KDE Framew...
vendor_debian·2016·CVSS 7.5
CVE-2016-6232 [HIGH] CVE-2016-6232: karchive - Directory traversal vulnerability in KArchive before 5.24, as used in KDE Framew...
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
Scope: local
bookworm: resolved (fixed in 5.24.0-1)
bullseye: resolved (fixed in 5.24.0-1)
forky: resolved (fixed in 5.24.0-1)
sid: resolved (fixed in 5.24.0-1)
trixie: resolved (fixed in 5.24.0-1)
GHSA
GHSA-5r9j-pp34-8hph: Directory traversal vulnerability in KArchive before 5
ghsa_unreviewed·2022-05-17
CVE-2016-6232 [HIGH] CWE-22 GHSA-5r9j-pp34-8hph: Directory traversal vulnerability in KArchive before 5
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
OSV
kconfig, kde4libs vulnerabilities
osv·2019-08-16·CVSS 7.5
CVE-2019-14744 [HIGH] kconfig, kde4libs vulnerabilities
kconfig, kde4libs vulnerabilities
It was discovered that KConfig and KDE libraries have a vulnerability
where an attacker could hide malicious code under desktop and
configuration files. (CVE-2019-14744)
It was discovered that KConfig allows remote attackers to write to
arbitrary files via a ../ in a filename in an archive file. (CVE-2016-6232)
OSV
CVE-2016-6232: Directory traversal vulnerability in KArchive before 5
osv·2016-08-02·CVSS 7.5
CVE-2016-6232 [HIGH] CVE-2016-6232: Directory traversal vulnerability in KArchive before 5
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-14744 kdelibs3: kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction [epel-7]
bugzilla·2019-08-12·CVSS 7.8
CVE-2019-14744 [HIGH] CVE-2019-14744 kdelibs3: kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction [epel-7]
CVE-2019-14744 kdelibs3: kdelibs: malicious desktop files and configuration files lead to code execution with minimal user interaction [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit
Bugzilla
CVE-2016-6232 kf5-karchive: Extraction of tar files possible to arbitrary system locations [epel-7]
bugzilla·2016-07-18·CVSS 7.5
CVE-2016-6232 [HIGH] CVE-2016-6232 kf5-karchive: Extraction of tar files possible to arbitrary system locations [epel-7]
CVE-2016-6232 kf5-karchive: Extraction of tar files possible to arbitrary system locations [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created by
Bugzilla
CVE-2016-6232 kf5-karchive: Extraction of tar files possible to arbitrary system locations [fedora-all]
bugzilla·2016-07-18·CVSS 7.5
CVE-2016-6232 [HIGH] CVE-2016-6232 kf5-karchive: Extraction of tar files possible to arbitrary system locations [fedora-all]
CVE-2016-6232 kf5-karchive: Extraction of tar files possible to arbitrary system locations [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
Bugzilla
CVE-2016-6232 kf5-karchive: Extraction of tar files possible to arbitrary system locations
bugzilla·2016-07-18·CVSS 7.5
CVE-2016-6232 [HIGH] CVE-2016-6232 kf5-karchive: Extraction of tar files possible to arbitrary system locations
CVE-2016-6232 kf5-karchive: Extraction of tar files possible to arbitrary system locations
When using KNewStuff, one of the KDE Frameworks, to download and install files
from the internet (e.g. a wallpaper, a plasma applet, etc.), it was possible
to download a maliciously crafted archive file (e.g. tar.gz or zip) containing
relative paths leading to outside the extraction directory (say
"../../../.bashrc" for instance).
References:
http://seclists.org/oss-sec/2016/q3/78
Upstream fix:
https://quickgit.kde.org/?p=karchive.git&a=commit&h=0cb243f64eef45565741b27364cece7d5c349c37
Discussion:
Created kf5-karchive tracking bugs for this issue:
Affects: fedora-all [bug 1357411]
Affects: epel-7 [bug 1357412]
---
breeze-icon-theme-5.24.0-1.fc24, extra-cmake-modules-5.24.0-1.fc24, kf5-5.24.
http://lists.opensuse.org/opensuse-security-announce/2016-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-09/msg00000.htmlhttp://www.debian.org/security/2016/dsa-3643http://www.openwall.com/lists/oss-security/2016/07/16/2http://www.openwall.com/lists/oss-security/2016/07/16/3http://www.securityfocus.com/bid/91806http://www.ubuntu.com/usn/USN-3042-1https://quickgit.kde.org/?p=karchive.git&a=commit&h=0cb243f64eef45565741b27364cece7d5c349c37https://usn.ubuntu.com/4100-1/https://www.kde.org/info/security/advisory-20160724-1.txthttp://lists.opensuse.org/opensuse-security-announce/2016-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-09/msg00000.htmlhttp://www.debian.org/security/2016/dsa-3643http://www.openwall.com/lists/oss-security/2016/07/16/2http://www.openwall.com/lists/oss-security/2016/07/16/3http://www.securityfocus.com/bid/91806http://www.ubuntu.com/usn/USN-3042-1https://quickgit.kde.org/?p=karchive.git&a=commit&h=0cb243f64eef45565741b27364cece7d5c349c37https://usn.ubuntu.com/4100-1/https://www.kde.org/info/security/advisory-20160724-1.txt
2016-08-02
Published