Bug 1018969

Summary: VUL-0: ark: unintended execution of scripts and executable files on "Open" functionality
Product: [Novell Products] SUSE Security Incidents Reporter: Mikhail Kasimov <mikhail.kasimov>
Component: IncidentsAssignee: Fabian Vogt <fabian>
Status: RESOLVED DUPLICATE QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P5 - None CC: astieger, kde-maintainers, meissner
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Mikhail Kasimov 2017-01-10 00:37:54 UTC
Ref: http://seclists.org/oss-sec/2017/q1/45

===============================================
Hi, Albert from KDE, can we get a CVE assigned for ark (archive handling 
tool)?

The problem is that the "Open" functionality of ark would run shell scripts, 
this is quite unexpected.

The title for the advisory we're preparing is
  Ark: unintended execution of scripts and executable files

The fix is already available at
https://cgit.kde.org/ark.git/commit/?id=82fdfd24d46966a117fa625b68784735a40f9065

Thanks,
  Albert
===============================================
Comment 1 Mikhail Kasimov 2017-01-10 00:43:42 UTC
https://software.opensuse.org/package/ark
Comment 2 Andreas Stieger 2017-01-10 08:10:29 UTC
dup of bug 1018648

*** This bug has been marked as a duplicate of bug 1018648 ***