Oval Definition:oval:org.cisecurity:def:1023
Revision Date:2016-09-16Version:6
Title:DSA-3643-1 -- kde4libs -- security update
Description:Andreas Cord-Landwehr discovered that kde4libs, the core libraries for all KDE 4 applications, do not properly handle the extraction of archives with "../" in the file paths. A remote attacker can take advantage of this flaw to overwrite files outside of the extraction folder, if a user is tricked into extracting a specially crafted archive.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2016-6232
DSA-3643-1
Platform(s):Debian 8
Product(s):kde4libs
Definition Synopsis
  • Debian 8 is installed
  • AND kde4libs is earlier than 4:4.14.2-5+deb8u1
  • BACK