CVE-2017-5330OS Command Injection in ARK

Severity
7.8HIGHNVD
EPSS
0.5%
top 33.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 27
Latest updateMay 17

Description

ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

Debiankde/ark< 4:16.08.3-2+3
NVDkde/ark16.12

Also affects: Fedora 25

Patches

🔴Vulnerability Details

3
GHSA
GHSA-fvqq-96pq-qq6m: ark before 162022-05-17
CVEList
CVE-2017-5330: ark before 162017-03-27
OSV
CVE-2017-5330: ark before 162017-03-27

📋Vendor Advisories

2
Red Hat
ark: Unintended execution of scripts and executable files2017-01-10
Debian
CVE-2017-5330: ark - ark before 16.12.1 might allow remote attackers to execute arbitrary code via an...2017

💬Community

2
Bugzilla
CVE-2017-5330 ark: Unintended execution of scripts and executable files2017-01-10
Bugzilla
CVE-2017-5330 ark: Unintended execution of scripts and executable files [fedora-all]2017-01-10
CVE-2017-5330 — OS Command Injection in KDE ARK | cvebase