In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "4:15.12.3-0ubuntu1.2", "binary_name": "ark" }, { "binary_version": "4:15.12.3-0ubuntu1.2", "binary_name": "ark-dbg" }, { "binary_version": "4:15.12.3-0ubuntu1.2", "binary_name": "ark-dbgsym" } ] }