KDE Linux desktop: security hole in Ark allowed remote attacks
Summary
In 2020 the KDE archive manager Ark contained a path traversal hole (CVE-2020-16116) through which prepared archives could write files to arbitrary locations in the home directory. This could be used, for example, to place a manipulated .bashrc or a script in the autostart folder, but the user had to extract the archive. Ark 20.08.0 prevented this and also issued a warning.
Ideas
- Paths with “../” in archives can break out of the target directory.
- Files such as .bashrc or autostart entries execute code at the next login.
- A proof of concept was already available on GitHub.
- heise corrected its original classification as a remote attack.
Insights
- Extracting is a write operation with foreign file names and needs the same care as code execution.
- Persistence via configuration files in the home directory is an underestimated attack path.
Facts
- Ark versions up to 20.04.3 were vulnerable.
- Besides 20.08.0, KDE offered a patch for older versions.
References
Critique
- The report had to be corrected afterwards because it initially classified the attack vector incorrectly as a remote attack.
Recommendations
- Extract archives of unknown origin only after listing their contents and checking the paths.
- Use tools that reject paths outside the target directory.
Links to the original source and the Web Archive open in a new tab.