Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Mon, 09 Jan 2017 23:52:08 +0100
From: Albert Astals Cid <aacid@....org>
To: OSS Security Mailinglist <oss-security@...ts.openwall.com>, security@....org
Subject: ark vulnerability: need CVE

Hi, Albert from KDE, can we get a CVE assigned for ark (archive handling 
tool)?

The problem is that the "Open" functionality of ark would run shell scripts, 
this is quite unexpected.

The title for the advisory we're preparing is
  Ark: unintended execution of scripts and executable files

The fix is already available at
https://cgit.kde.org/ark.git/commit/?
id=82fdfd24d46966a117fa625b68784735a40f9065

Thanks,
  Albert

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ