CVE-2020-24654
published 2020-09-02CVE-2020-24654: In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a…
PriorityP415low3.3CVSS 3.1
AVLACLPRNUIRSUCNILAN
EPSS
1.50%
71.3th percentile
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | ark | < ark 4:20.08.1-1 (bookworm) | ark 4:20.08.1-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| kde | ark | < 20.08.1 | 20.08.1 |
| kde | ark | >= 0 < 4:20.08.1-1 | 4:20.08.1-1 |
| kde | ark | >= 0 < 4:20.08.1-1 | 4:20.08.1-1 |
| kde | ark | >= 0 < 4:20.08.1-1 | 4:20.08.1-1 |
| kde | ark | >= 0 < 4:20.08.1-1 | 4:20.08.1-1 |
| opensuse | leap | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Ark vulnerability
vendor_ubuntu·2020-09-01
CVE-2020-24654 Ark vulnerability
Title: Ark vulnerability
Summary: Ark could be made to write files as your login if it opened a specially
crafted file.
Fabian Vogt discovered that Ark incorrectly handled symbolic links in
tar archive files. An attacker could use this to construct a malicious
tar archive that, when opened, would create files outside the extraction
directory.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ark: crafted TAR archive with symlinks can install files outside the extraction directory
vendor_redhat·2020-08-27·CVSS 3.3
CVE-2020-24654 [LOW] CWE-59 ark: crafted TAR archive with symlinks can install files outside the extraction directory
ark: crafted TAR archive with symlinks can install files outside the extraction directory
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
Mitigation: The way to mitigate this flaw is to pay attention to the contents of the archive in ark before extracting, to ensure that there are no improper symlinks, and heed the file overwrite warnings.
Package: ark (Red Hat Enterprise Linux 7) - Fix deferred
Debian
CVE-2020-24654: ark - In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files...
vendor_debian·2020·CVSS 3.3
CVE-2020-24654 [LOW] CVE-2020-24654: ark - In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files...
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
Scope: local
bookworm: resolved (fixed in 4:20.08.1-1)
bullseye: resolved (fixed in 4:20.08.1-1)
forky: resolved (fixed in 4:20.08.1-1)
sid: resolved (fixed in 4:20.08.1-1)
trixie: resolved (fixed in 4:20.08.1-1)
GHSA
GHSA-wc24-5j7x-rp2x: In KDE Ark before 20
ghsa_unreviewed·2022-05-24
CVE-2020-24654 [MEDIUM] CWE-59 GHSA-wc24-5j7x-rp2x: In KDE Ark before 20
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
OSV
CVE-2020-24654: In KDE Ark before 20
osv·2020-09-02·CVSS 3.3
CVE-2020-24654 [LOW] CVE-2020-24654: In KDE Ark before 20
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00001.htmlhttps://bugzilla.suse.com/show_bug.cgi?id=1175857https://github.com/KDE/ark/commit/8bf8c5ef07b0ac5e914d752681e470dea403a5bdhttps://kde.org/info/security/advisory-20200827-1.txthttps://lists.debian.org/debian-lts-announce/2022/05/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LXMMXNJDYOCJRZTESIUGHG6CS4RJKECX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJOZ6YRNPZX5MJGVBMOCOA7N6Z4EU2OK/https://security.gentoo.org/glsa/202010-06https://security.gentoo.org/glsa/202101-06https://usn.ubuntu.com/4482-1/https://www.debian.org/security/2020/dsa-4759http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00001.htmlhttps://bugzilla.suse.com/show_bug.cgi?id=1175857https://github.com/KDE/ark/commit/8bf8c5ef07b0ac5e914d752681e470dea403a5bdhttps://kde.org/info/security/advisory-20200827-1.txthttps://lists.debian.org/debian-lts-announce/2022/05/msg00026.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LXMMXNJDYOCJRZTESIUGHG6CS4RJKECX/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YJOZ6YRNPZX5MJGVBMOCOA7N6Z4EU2OK/https://security.gentoo.org/glsa/202010-06https://security.gentoo.org/glsa/202101-06https://usn.ubuntu.com/4482-1/https://www.debian.org/security/2020/dsa-4759
2020-09-02
Published