CVE-2016-6232: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 4.4% chance of exploitation in the next 30 days.
Directory traversal vulnerability in KArchive before 5.24, as used in KDE Frameworks, allows remote attackers to write to arbitrary files via a ../ (dot dot slash) in a filename in an archive file, related to KNewsstuff downloads.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
- Kde Karchives: up to and including 5.24
Published 2016-08-02. Last modified 2026-06-17.