From abaa75b10f899ada8dd05b23cc03205064394bc6 Mon Sep 17 00:00:00 2001 From: V3n3RiX Date: Fri, 22 Jan 2021 20:28:19 +0000 Subject: gentoo resync : 22.01.2021 --- metadata/glsa/glsa-202101-06.xml | 49 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 49 insertions(+) create mode 100644 metadata/glsa/glsa-202101-06.xml (limited to 'metadata/glsa/glsa-202101-06.xml') diff --git a/metadata/glsa/glsa-202101-06.xml b/metadata/glsa/glsa-202101-06.xml new file mode 100644 index 000000000000..efa0c4ddc2f8 --- /dev/null +++ b/metadata/glsa/glsa-202101-06.xml @@ -0,0 +1,49 @@ + + + + Ark: Symlink vulnerability + Ark was found to allow arbitrary file overwrite, possibly allowing + arbitrary code execution. + + ark + 2021-01-11 + 2021-01-11 + 743959 + remote + + + 20.04.3-r2 + 20.04.3-r2 + + + +

Ark is a graphical file compression/decompression utility with support + for multiple formats. +

+
+ +

KDE Ark did not fully verify symlinks contained within tar archives.

+
+ +

A remote attacker could entice a user to open a specially crafted tar + archive using KDE Ark, possibly resulting in execution of arbitrary code + with the privileges of the process or a Denial of Service condition. +

+
+ +

There is no known workaround at this time.

+
+ +

All KDE Ark users should upgrade to the latest version:

+ + + # emerge --sync + # emerge --ask --oneshot --verbose ">=kde-apps/ark-20.04.3-r2" + +
+ + CVE-2020-24654 + + sam_c + sam_c +
-- cgit v1.2.3