CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-57966: libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.

5.0 CVSS

Description

libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.

Classification

CVE ID: CVE-2024-57966

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.0

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:L

Affected Products

Vendor: KDE

Product: ark

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.83% (scored less or equal to compared to others)

EPSS Date: 2025-03-04 (when was this score calculated)

References

https://github.com/KDE/ark/commit/fe518d81b338941e0bf1c5ce5e75a9ab6de4bb58
https://github.com/KDE/ark/compare/v24.11.90...v24.12.0

Timeline