SVN commit 12945 by tcberner:

Add upstream patch for a security issue in karchive:
        Directory traversal vulnerability in KArchive before 5.24, as 
        used in KDE Frameworks, allows remote attackers to write to
        arbitrary files via a ../ (dot dot slash) in a filename in an 
        archive file, related to KNewsstuff downloads.

Review the patch is from: https://git.reviewboard.kde.org/r/128749/
Original KF5 review: https://git.reviewboard.kde.org/r/128185/
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-6232




 AM            patch-cr-128749  


Reply via email to