Debian Security Advisory 3643-1

Discussion in 'News Aggregator' started by Packet Storm, 10 Aug 2016.

  1. Packet Storm

    Packet Storm Guest

    Debian Linux Security Advisory 3643-1 - Andreas Cord-Landwehr discovered that kde4libs, the core libraries for all KDE 4 applications, do not properly handle the extraction of archives with "../" in the file paths. A remote attacker can take advantage of this flaw to overwrite files outside of the extraction folder, if a user is tricked into extracting a specially crafted archive.

    Continue reading...
     

Share This Page

Loading...