A maliciously crafted TAR archive containing symlink entries would install files anywhere in the user's home directory upon extraction (CVE-2020-24654). References: - https://bugs.mageia.org/show_bug.cgi?id=27214 . MGASA-2020-0353 - Updated ark packages fix security vulnerability Publication date: 29 Aug 2020 URL: https://advisories.mageia.org/MGASA-2020-0353.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-24654 A maliciously crafted TAR archive containing symlink entries would install files anywhere in the user's home directory upon extraction (CVE-2020-24654). References: - https://bugs.mageia.org/show_bug.cgi?id=27214 - https://kde.org/info/security/advisory-20200827-1.txt - https://www.cve.org/CVERecord?id=CVE-2020-24654 SRPMS: - 7/core/ark-19.04.0-1.2.mga7 . A malicious TAR package can present security threats by placing files in user folders. Revised information for Mageia 7 has been incorporated.. Mageia Security Update, Ark Package Vulnerability, TAR Archive Security Issue, Malware Risk in TAR, Mageia 2020 Advisory. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.