Alerts This Week
Warning Icon 1 1,394
Alerts This Week
Warning Icon 1 1,394

Ubuntu 20.04 LTS: 4461-1 Critical: Ark File Extraction Risk

ubuntu
Calendar Grey August 18, 2020
Dist Ubuntu Esm H88
A serious vulnerability in the Ark application on Ubuntu could allow unauthorized file changes during user login, creating major security risks. Apply updates promptly to protect your systems
Ark could be made to write files as your login if it opened a specially crafted file.

Summary

Ark could be made to write files as your login if it opened a specially

crafted file.

Software Description:

- ark: archive utility

Details:

Dominik Penner discovered that Ark did not properly sanitize zip archive

files before performing extraction. An attacker could use this to construct

a malicious zip archive that, when opened, would create files outside the

extraction directory.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  ark                             4:19.12.3-0ubuntu1.1

Ubuntu 18.04 LTS:
  ark                             4:17.12.3-0ubuntu1.1

After a standard system update you need to restart Ark to make all
the necessary changes.

References

https://ubuntu.com/security/notices/USN-4461-1

CVE-2020-16116

Severity
critical
Lowest
Low
Medium
High
Critical

August 18, 2020

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here