CVE-2020-16116
published 2020-08-03CVE-2020-16116: In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
PriorityP416low3.3CVSS 3.1
AVLACLPRNUIRSUCNILAN
EPSS
1.71%
75.0th percentile
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | ark | < ark 4:20.04.3-1 (bookworm) | ark 4:20.04.3-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| kde | ark | < 20.08.0 | 20.08.0 |
| kde | ark | >= 0 < 4:20.04.3-1 | 4:20.04.3-1 |
| kde | ark | >= 0 < 4:20.04.3-1 | 4:20.04.3-1 |
| kde | ark | >= 0 < 4:20.04.3-1 | 4:20.04.3-1 |
| kde | ark | >= 0 < 4:20.04.3-1 | 4:20.04.3-1 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2q6p-c398-62rm: In kerfuffle/jobs
ghsa_unreviewed·2022-05-24
CVE-2020-16116 [MEDIUM] CWE-22 GHSA-2q6p-c398-62rm: In kerfuffle/jobs
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
OSV
CVE-2020-16116: In kerfuffle/jobs
osv·2020-08-03·CVSS 3.3
CVE-2020-16116 [LOW] CVE-2020-16116: In kerfuffle/jobs
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
Ubuntu
Ark vulnerability
vendor_ubuntu·2020-08-18
CVE-2020-16116 Ark vulnerability
Title: Ark vulnerability
Summary: Ark could be made to write files as your login if it opened a specially
crafted file.
Dominik Penner discovered that Ark did not properly sanitize zip archive
files before performing extraction. An attacker could use this to construct
a malicious zip archive that, when opened, would create files outside the
extraction directory.
Instructions: After a standard system update you need to restart Ark to make all
the necessary changes.
Red Hat
ark: maliciously crafted archive can install files anywhere in the user's home directory
vendor_redhat·2020-07-30·CVSS 3.3
CVE-2020-16116 [LOW] CWE-552 ark: maliciously crafted archive can install files anywhere in the user's home directory
ark: maliciously crafted archive can install files anywhere in the user's home directory
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
Statement: ark as shipped with Red Hat Enterprise Linux 7 prompts the user before allowing extraction into home directory, and also displays an error. Because the user must agree to perform the extraction in the home directory, Red Hat Product Security does not view this as a security vulnerability in ark as shipped with Red Hat Enterprise Linux 7.
Package: ark (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2020-16116: ark - In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install f...
vendor_debian·2020·CVSS 3.3
CVE-2020-16116 [LOW] CVE-2020-16116: ark - In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install f...
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
Scope: local
bookworm: resolved (fixed in 4:20.04.3-1)
bullseye: resolved (fixed in 4:20.04.3-1)
forky: resolved (fixed in 4:20.04.3-1)
sid: resolved (fixed in 4:20.04.3-1)
trixie: resolved (fixed in 4:20.04.3-1)
No detection rules found.
Bugzilla
CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory
bugzilla·2020-07-31·CVSS 3.3
CVE-2020-16116 [LOW] CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory
CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory
A maliciously crafted archive with "../" in the file paths would install files anywhere in the user's home directory upon extraction.
External Reference:
https://bugs.gentoo.org/734622
Discussion:
Created ark tracking bugs for this issue:
Affects: epel-8 [bug 1862466]
Affects: fedora-all [bug 1862465]
---
it's fixed in ark-20.04.3-3
---
FEDORA-2020-cac5ae9b6e has been pushed to the Fedora 31 stable repository.
If problem still persists, please make note of it in this bug report.
---
Statement:
ark as shipped with Red Hat Enterprise Linux 7 prompts the user before allowing extraction into home directory, and also displays an error. Because the user must agree to perform the e
Bugzilla
CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory [epel-8]
bugzilla·2020-07-31·CVSS 3.3
CVE-2020-16116 [LOW] CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory [epel-8]
CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory [epel-8]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-8.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the
Bugzilla
CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory [fedora-all]
bugzilla·2020-07-31·CVSS 3.3
CVE-2020-16116 [LOW] CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory [fedora-all]
CVE-2020-16116 ark: maliciously crafted archive can install files anywhere in the user's home directory [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this is
http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00023.htmlhttps://github.com/KDE/ark/commits/masterhttps://invent.kde.org/utilities/ark/-/commit/0df592524fed305d6fbe74ddf8a196bc9ffdb92fhttps://kde.org/info/security/advisory-20200730-1.txthttps://lists.debian.org/debian-lts-announce/2022/05/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PMVXSQNCBILVSJLX32ODNU6KUY2X7HRM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PYRKQKUVU45ANH5TFYCYZN6HVP34N3UL/https://security.gentoo.org/glsa/202008-03https://usn.ubuntu.com/4461-1/https://www.debian.org/security/2020/dsa-4738http://lists.opensuse.org/opensuse-security-announce/2020-08/msg00023.htmlhttps://github.com/KDE/ark/commits/masterhttps://invent.kde.org/utilities/ark/-/commit/0df592524fed305d6fbe74ddf8a196bc9ffdb92fhttps://kde.org/info/security/advisory-20200730-1.txthttps://lists.debian.org/debian-lts-announce/2022/05/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PMVXSQNCBILVSJLX32ODNU6KUY2X7HRM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PYRKQKUVU45ANH5TFYCYZN6HVP34N3UL/https://security.gentoo.org/glsa/202008-03https://usn.ubuntu.com/4461-1/https://www.debian.org/security/2020/dsa-4738
2020-08-03
Published