• Ark vulnerability

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Tuesday, August 18, 2020 04:10:03
    ark vulnerability

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 20.04 LTS
    * Ubuntu 18.04 LTS

    Summary

    Ark could be made to write files as your login if it opened a
    specially crafted file.

    Software Description

    * ark - archive utility

    Details

    Dominik Penner discovered that Ark did not properly sanitize zip
    archive files before performing extraction. An attacker could use
    this to construct a malicious zip archive that, when opened, would
    create files outside the extraction directory.

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 20.04 LTS
    ark - 4:19.12.3-0ubuntu1.1

    Ubuntu 18.04 LTS
    ark - 4:17.12.3-0ubuntu1.1

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    After a standard system update you need to restart Ark to make all
    the necessary changes.

    References

    * CVE-2020-16116

    --- Mystic BBS v1.12 A45 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)
  • From bugz_ubuntu@21:4/110 to Ubuntu Users on Tuesday, September 01, 2020 20:10:03
    ark vulnerability

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 20.04 LTS
    * Ubuntu 18.04 LTS
    * Ubuntu 16.04 LTS

    Summary

    Ark could be made to write files as your login if it opened a
    specially crafted file.

    Software Description

    * ark - archive utility

    Details

    Fabian Vogt discovered that Ark incorrectly handled symbolic links
    in tar archive files. An attacker could use this to construct a
    malicious tar archive that, when opened, would create files
    outside the extraction directory.

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 20.04 LTS
    ark - 4:19.12.3-0ubuntu1.2

    Ubuntu 18.04 LTS
    ark - 4:17.12.3-0ubuntu1.2

    Ubuntu 16.04 LTS
    ark - 4:15.12.3-0ubuntu1.2

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    In general, a standard system update will make all the necessary
    changes.

    References

    * CVE-2020-24654

    --- Mystic BBS v1.12 A46 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)