USN-1276-1: KDE Utilities vulnerability
21 November 2011
Ark could be made to remove files.
Releases
Packages
- kdeutils - KDE general-purpose utilities
Details
Tim Brown discovered that Ark did not properly perform input validation
when previewing archive files. If a user were tricked into opening a
crafted archive file, an attacker could remove files via directory
traversal.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 11.10
Ubuntu 11.04
Ubuntu 10.10
Ubuntu 10.04
After a standard system update you need to restart your session to make
all the necessary changes.
NOTE: In order to build KDE Utilities on Ubuntu 10.04 LTS, 10.10 and 11.04, it
was necessary to rebuild portions of the KDE point release updates.