In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
CVSS Details
- CVSS 3.1 Base Score: 3.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ark | Aug 22, 2024 | Sep 2, 2020 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Sep 2, 2020 |
| Debian | — | Upgrade ark | Sep 8, 2020 | Sep 2, 2020 |
| Freebsd | — | Upgrade ark | Aug 29, 2020 | Aug 28, 2020 |
| Gentoo Linux | — | Upgrade kde-apps/ark. | Oct 21, 2020 | Sep 2, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Sep 2, 2020 |
| Suse | — | Upgrade libkerfuffle20Upgrade libkerfuffle18Upgrade arkUpgrade ark-lang | Sep 2, 2020 | Aug 27, 2020 |
| Ubuntu | — | Upgrade ark | Sep 2, 2020 | Aug 27, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub