Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Joran Herve

#45305de 53,638
5.5CVSS total
Vulnerabilidades · 1
PT-2018-9527
5.5
2018-09-06
Kde · Okular · CVE-2018-1000801
**Name of the Vulnerable Software and Affected Versions** okular versions prior to 18.08.1 **Description** The issue is related to a Directory Traversal vulnerability in the `unpackDocumentArchive(...)` function located in `core/document.cpp`. This can lead to Arbitrary file creation on the user workstation. The attack is exploitable when the victim opens a specially crafted Okular archive. **Recommendations** For okular versions prior to 18.08.1, update to version 18.08.1 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the `unpackDocumentArchive(...)` function until a patch is available. Restrict access to specially crafted Okular archives to minimize the risk of exploitation.