Advisories ยป MGASA-2020-0353

Updated ark packages fix security vulnerability

Publication date: 29 Aug 2020
Modification date: 29 Aug 2020
Type: security
Affected Mageia releases : 7
CVE: CVE-2020-24654

Description

A maliciously crafted TAR archive containing symlink entries would install
files anywhere in the user's home directory upon extraction (CVE-2020-24654).
                

References

SRPMS

7/core