High severity7.5NVD Advisory· Published Aug 2, 2016· Updated May 6, 2026
CVE-2016-6232
CVE-2016-6232
Description
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.ubuntu.com/usn/USN-3042-1nvdPatch
- www.kde.org/info/security/advisory-20160724-1.txtnvdExploitMitigationVendor Advisory
- www.openwall.com/lists/oss-security/2016/07/16/3nvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2016-07/msg00023.htmlnvd
- lists.opensuse.org/opensuse-security-announce/2016-09/msg00000.htmlnvd
- www.debian.org/security/2016/dsa-3643nvd
- www.openwall.com/lists/oss-security/2016/07/16/2nvd
- www.securityfocus.com/bid/91806nvd
- quickgit.kde.orgnvd
- usn.ubuntu.com/4100-1/nvd
News mentions
0No linked articles in our index yet.