[Bug 1712948] Re: [CVE] KNewstuff downloads can install files outside the extraction directory

Simon Quigley tsimonq2 at ubuntu.com
Sun Sep 3 01:10:04 UTC 2017


Attached is a debdiff for Xenial applicable to 5.18.0-0ubuntu1. I tested
this on a fresh, fully updated Kubuntu 16.04 install and it works fine
(without regression).

** Patch added: "1-5.18.0-0ubuntu1.1.debdiff"
   https://bugs.launchpad.net/ubuntu/+source/karchive/+bug/1712948/+attachment/4943304/+files/1-5.18.0-0ubuntu1.1.debdiff

** Changed in: karchive (Ubuntu Xenial)
    Milestone: None => xenial-updates

-- 
You received this bug notification because you are a member of Kubuntu
Bugs, which is subscribed to karchive in Ubuntu.
https://bugs.launchpad.net/bugs/1712948

Title:
  [CVE] KNewstuff downloads can install files outside the extraction
  directory

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/karchive/+bug/1712948/+subscriptions




More information about the kubuntu-bugs mailing list