Vulnerability Bulletins

DSA-3643 kde4libs - security update

   
Affected software Debian
 
Andreas Cord-Landwehr discovered that kde4libs, the core librariesfor all KDE 4 applications, do not properly handle the extractionof archives with "../" in the file paths. A remote attacker cantake advantage of this flaw to overwrite files outside of theextraction folder, if a user is tricked into extracting a speciallycrafted archive.

More info:

https://www.debian.org/security/2016/dsa-3643