vulnerability

Oracle Linux: CVE-2018-1000801: ELSA-2020-1173: okular security update (MODERATE)

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:P/A:N)
Published
Sep 6, 2018
Added
Oct 5, 2022
Modified
Dec 3, 2025

Description

okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be exploitable via he victim must open a specially crafted Okular archive. This issue appears to have been corrected in version 18.08.1
A path traversal vulnerability has been discovered in Okular, in the way it creates temporary files when reading an Okular archive. Paths are read from content.xml and they are not properly sanitized before being used as template file names for the temporary files created when extracting the Okular archive, thus allowing a local attacker to write files outside the target temporary directory.

Solutions

oracle-linux-upgrade-okularoracle-linux-upgrade-okular-develoracle-linux-upgrade-okular-libsoracle-linux-upgrade-okular-part
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.