Lucene search

K
ubuntuUbuntuUSN-4482-1
HistorySep 01, 2020 - 12:00 a.m.

Ark vulnerability

2020-09-0100:00:00
ubuntu.com
53
ark
ubuntu
vulnerability
symbolic links
tar archive
malicious files
extraction

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

3.4

Confidence

High

EPSS

0.003

Percentile

68.5%

Releases

  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM
  • Ubuntu 16.04 ESM

Packages

  • ark - archive utility

Details

Fabian Vogt discovered that Ark incorrectly handled symbolic links in
tar archive files. An attacker could use this to construct a malicious
tar archive that, when opened, would create files outside the extraction
directory.

OSVersionArchitecturePackageVersionFilename
Ubuntu20.04noarchark< 4:19.12.3-0ubuntu1.2UNKNOWN
Ubuntu20.04noarchark-dbgsym< 4:19.12.3-0ubuntu1.2UNKNOWN
Ubuntu18.04noarchark< 4:17.12.3-0ubuntu1.2UNKNOWN
Ubuntu18.04noarchark-dbgsym< 4:17.12.3-0ubuntu1.2UNKNOWN
Ubuntu16.04noarchark< 4:15.12.3-0ubuntu1.2UNKNOWN
Ubuntu16.04noarchark-dbg< 4:15.12.3-0ubuntu1.2UNKNOWN
Ubuntu16.04noarchark-dbgsym< 4:15.12.3-0ubuntu1.2UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

AI Score

3.4

Confidence

High

EPSS

0.003

Percentile

68.5%