Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 9: MGASA-2025-0061 Critical Threat: Ark Path Extraction Risk

mageia
Calendar Grey February 13, 2025
Dist Mageia Esm H88
Investigate the Mageia security notice MGASA-2025-0061 detailing a vulnerability in ark that permits unauthorized access for file extraction.
A security issue exists in Ark where a maliciously crafted archive containing file paths beginning with "/" allows files to be extracted to locations outside the intended directory

Summary

A security issue exists in Ark where a maliciously crafted archive containing file paths beginning with "/" allows files to be extracted to locations outside the intended directory.

References

- https://bugs.mageia.org/show_bug.cgi?id=34013

- https://kde.org/info/security/advisory-20250207-1.txt

- https://www.cve.org/CVERecord?id=CVE-2024-57966

Resolution

SRPMS

- 9/core/ark-23.04.3-1.1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 13 Feb 2025
URL: https://advisories.mageia.org/MGASA-2025-0061.html
Type: security
CVE: CVE-2024-57966

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here