bk99.de entertain the web since 1997

KDE Linux desktop: security hole in Ark allowed remote attacks

Summary

In 2020 the KDE archive manager Ark contained a path traversal hole (CVE-2020-16116) through which prepared archives could write files to arbitrary locations in the home directory. This could be used, for example, to place a manipulated .bashrc or a script in the autostart folder, but the user had to extract the archive. Ark 20.08.0 prevented this and also issued a warning.

Ideas

  • Paths with “../” in archives can break out of the target directory.
  • Files such as .bashrc or autostart entries execute code at the next login.
  • A proof of concept was already available on GitHub.
  • heise corrected its original classification as a remote attack.

Insights

  • Extracting is a write operation with foreign file names and needs the same care as code execution.
  • Persistence via configuration files in the home directory is an underestimated attack path.

Facts

  • Ark versions up to 20.04.3 were vulnerable.
  • Besides 20.08.0, KDE offered a patch for older versions.

References

Critique

  • The report had to be corrected afterwards because it initially classified the attack vector incorrectly as a remote attack.

Recommendations

  • Extract archives of unknown origin only after listing their contents and checking the paths.
  • Use tools that reject paths outside the target directory.

Read the original article

Search the Web Archive