libarchiveplugin.cpp in KDE ark before 24.12.0 can extract to an absolute path from an archive.
{ "vanir_signatures": [ { "signature_version": "v1", "source": "https://github.com/kde/ark/commit/fe518d81b338941e0bf1c5ce5e75a9ab6de4bb58", "signature_type": "Function", "target": { "function": "LibarchivePlugin::extractionFlags", "file": "plugins/libarchive/libarchiveplugin.cpp" }, "deprecated": false, "digest": { "length": 153.0, "function_hash": "92950249168408824949588827210376077342" }, "id": "CVE-2024-57966-817be60b" }, { "signature_version": "v1", "source": "https://github.com/kde/ark/commit/fe518d81b338941e0bf1c5ce5e75a9ab6de4bb58", "signature_type": "Line", "target": { "file": "plugins/libarchive/libarchiveplugin.cpp" }, "deprecated": false, "digest": { "line_hashes": [ "220204647504994727138907679677301311624", "222038716733348899504575798418846489909", "229032019905062076456928908007330015070", "65978093045713843273613591632343073311", "26735906475720014663809280306154077684", "73617774723263138499033682547975979456", "221547668275580750425446489519470341178", "260338842149791753201417877460226876978", "224597503903516629171941227306572650715", "339066316322557546373799136365671747786", "61825346247672945957102480452548455776" ], "threshold": 0.9 }, "id": "CVE-2024-57966-bd1f9628" }, { "signature_version": "v1", "source": "https://github.com/kde/ark/commit/fe518d81b338941e0bf1c5ce5e75a9ab6de4bb58", "signature_type": "Line", "target": { "file": "autotests/kerfuffle/extracttest.cpp" }, "deprecated": false, "digest": { "line_hashes": [ "332267113243607604279641050664915530879", "198775865366999714708383753794641788723", "137190222825344850611546818937876466641" ], "threshold": 0.9 }, "id": "CVE-2024-57966-f813b5de" }, { "signature_version": "v1", "source": "https://github.com/kde/ark/commit/fe518d81b338941e0bf1c5ce5e75a9ab6de4bb58", "signature_type": "Function", "target": { "function": "ExtractTest::testExtraction_data", "file": "autotests/kerfuffle/extracttest.cpp" }, "deprecated": false, "digest": { "length": 15280.0, "function_hash": "80977258953651137448340464034251151328" }, "id": "CVE-2024-57966-f85700cc" } ] }