CVE-2011-2725

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
04/02/2014
Last modified:
11/04/2025

Description

Directory traversal vulnerability in Ark 4.7.x and earlier allows remote attackers to delete and force the display of arbitrary files via .. (dot dot) sequences in a zip file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:kde:ark:*:*:*:*:*:*:*:* 2.17 (including)
cpe:2.3:a:kde:kde_sc:*:*:*:*:*:*:*:* 4.7.4 (including)
cpe:2.3:a:kde:kde_sc:4.7.0:*:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.7.1:*:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.7.2:*:*:*:*:*:*:*
cpe:2.3:a:kde:kde_sc:4.7.3:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.04:-:lts:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:10.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:11.10:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*