summaryrefslogtreecommitdiff
path: root/java/openjdk8/files/patch-jdk-src-share-classes-sun-misc-Version.java.template
diff options
context:
space:
mode:
authorTobias C. Berner <tcberner@FreeBSD.org>2020-07-30 04:32:24 +0000
committerTobias C. Berner <tcberner@FreeBSD.org>2020-07-30 04:32:24 +0000
commitc689c7af7b043392d9dc82bd74fd5ae8e580e611 (patch)
tree50b6594339975578d32b822f6142380bb8d4a709 /java/openjdk8/files/patch-jdk-src-share-classes-sun-misc-Version.java.template
parentastro/xearth: add myself (asomers) to freebsd.committers.markers (diff)
archivers/ark: security fix
KDE Project Security Advisory ============================= Title: Ark: maliciously crafted archive can install files outside the extraction directory. Risk Rating: Important CVE: CVE-2020-16116 Versions: ark <= 20.04.3 Author: Elvis Angelaccio <elvis.angelaccio@kde.org> Date: 30 July 2020 Overview ======== A maliciously crafted archive with "../" in the file paths would install files anywhere in the user's home directory upon extraction. Proof of concept ================ For testing, an example of malicious archive can be found at https://github.com/jwilk/traversal-archives/releases/download/0/relative2.zip Impact ====== Users can unwillingly install files like a modified .bashrc, or a malicious script placed in ~/.config/autostart Workaround ========== Users should not use the 'Extract' context menu from the Dolphin file manager. Before extracting a downloaded archive using the Ark GUI, users should inspect it to make sure it doesn't contain entries with "../" in the file path. Solution ======== Ark 20.08.0 prevents loading of malicious archives and shows a warning message to the users. Alternatively, https://invent.kde.org/utilities/ark/-/commit/0df592524fed305d6fbe74ddf8a196bc9ffdb92f can be applied to previous releases. Credits ======= Thanks to Dominik Penner for finding and reporting this issue and thanks to Elvis Angelaccio and Albert Astals Cid for fixing it.
Notes
Notes: svn path=/head/; revision=543704
Diffstat (limited to 'java/openjdk8/files/patch-jdk-src-share-classes-sun-misc-Version.java.template')
0 files changed, 0 insertions, 0 deletions