[SVN Commit] branches/plasma5/KDE/x11/kdelibs4/files

Tobias Berner tcberner at gmail.com
Thu Aug 25 20:36:10 UTC 2016


SVN commit 12945 by tcberner:

Add upstream patch for a security issue in karchive:
	Directory traversal vulnerability in KArchive before 5.24, as 
        used in KDE Frameworks, allows remote attackers to write to
        arbitrary files via a ../ (dot dot slash) in a filename in an 
        archive file, related to KNewsstuff downloads.

Review the patch is from: https://git.reviewboard.kde.org/r/128749/
Original KF5 review: https://git.reviewboard.kde.org/r/128185/
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6232




 AM            patch-cr-128749  




More information about the kde-freebsd mailing list