HomeCanonicalCVE-2016-6232

CVE-2016-6232

HIGH
7.5CVSS
Published: 2016-08-02
Updated: 2025-04-12
AI Analysis

Description

Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.

CVSS Metrics

Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
none
Integrity
high
Availability
none
Weaknesses
CWE-22

Metadata

Primary Vendor
CANONICAL
Published
8/2/2016
Last Modified
4/12/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

canonical : ubuntu_linuxcanonical : ubuntu_linuxcanonical : ubuntu_linuxkde : karchives

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2016-6232 | HIGH Severity | CVEDatabase.com | CVEDatabase.com