Back to search
CVE-2016-6232
Published: Aug 2, 2016
Modified: Aug 6, 2024
PUBLISHED
Description
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20160716 Re: CVE Request for KNewStuff/KArchive issue
mailing-list
x_refsource_MLIST
https://www.kde.org/info/security/advisory-20160724-1.txt
x_refsource_CONFIRM
openSUSE-SU-2016:1884
vendor-advisory
x_refsource_SUSE
91806
vdb-entry
x_refsource_BID
DSA-3643
vendor-advisory
x_refsource_DEBIAN
openSUSE-SU-2016:2223
vendor-advisory
x_refsource_SUSE
[oss-security] 20160716 CVE Request for KNewStuff/KArchive issue
mailing-list
x_refsource_MLIST
USN-3042-1
vendor-advisory
x_refsource_UBUNTU
USN-4100-1
vendor-advisory
x_refsource_UBUNTU
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now