Vulnerability Bulletins |
DSA-3643 kde4libs - security update |
|
| Affected software | Debian |
|
Andreas Cord-Landwehr discovered that kde4libs, the core librariesfor all KDE 4 applications, do not properly handle the extractionof archives with "../" in the file paths. A remote attacker cantake advantage of this flaw to overwrite files outside of theextraction folder, if a user is tricked into extracting a speciallycrafted archive. More info: https://www.debian.org/security/2016/dsa-3643 |
|






