UBUNTU-CVE-2018-1000801
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-1000801
UBUNTU-CVE-2018-1000801
Summary:
Details: okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be exploitable via he victim must open a specially crafted Okular archive. This issue appears to have been corrected in version 18.08.1
References: https://ubuntu.com/security/CVE-2018-1000801, https://bugs.kde.org/show_bug.cgi?id=398096, https://cgit.kde.org/okular.git/commit/?id=8ff7abc14d41906ad978b6bc67e69693863b9d47, https://ubuntu.com/security/notices/USN-4830-1, https://www.cve.org/CVERecord?id=CVE-2018-1000801
Affected packages
Package
Name: okular
Purl: pkg:deb/ubuntu/okular@4:15.12.3-0ubuntu1?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
