ark is vulnerable to directory traversal. An attacker is able to install files outside of the extraction directory using ../
characters.
lists.opensuse.org/opensuse-security-announce/2020-08/msg00023.html
github.com/KDE/ark/commits/master
invent.kde.org/utilities/ark/-/commit/0df592524fed305d6fbe74ddf8a196bc9ffdb92f
kde.org/info/security/advisory-20200730-1.txt
lists.debian.org/debian-lts-announce/2022/05/msg00026.html
lists.fedoraproject.org/archives/list/[email protected]/message/PMVXSQNCBILVSJLX32ODNU6KUY2X7HRM/
lists.fedoraproject.org/archives/list/[email protected]/message/PYRKQKUVU45ANH5TFYCYZN6HVP34N3UL/
security.gentoo.org/glsa/202008-03
usn.ubuntu.com/4461-1/
www.debian.org/security/2020/dsa-4738