[SVN Commit] branches/plasma5/KDE/x11/kdelibs4/files
Tobias Berner
tcberner at gmail.com
Thu Aug 25 20:36:10 UTC 2016
SVN commit 12945 by tcberner:
Add upstream patch for a security issue in karchive:
Directory traversal vulnerability in KArchive before 5.24, as
used in KDE Frameworks, allows remote attackers to write to
arbitrary files via a ../ (dot dot slash) in a filename in an
archive file, related to KNewsstuff downloads.
Review the patch is from: https://git.reviewboard.kde.org/r/128749/
Original KF5 review: https://git.reviewboard.kde.org/r/128185/
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6232
AM patch-cr-128749
More information about the kde-freebsd
mailing list