Jump to content

Advisories MDVSA-2010:122: fastjar


paul
 Share

Recommended Posts

A vulnerability has been discovered and corrected in fastjar:

 

Directory traversal vulnerability in the extract_jar function

in jartool.c in FastJar 0.98 allows remote attackers to create

or overwrite arbitrary files via a .. (dot dot) in a non-initial

pathname component in a filename within a .jar archive, a related

issue to CVE-2005-1080. NOTE: this vulnerability exists because of

an incomplete fix for CVE-2006-3619 (CVE-2010-0831).

 

Packages for 2008.0 and 2009.0 are provided as of the Extended

Maintenance Program. Please visit this link to learn more:

http://store.mandriva.com/product_info.php?cPath=149&products_id=490

 

The updated packages have been patched to correct this issue.

Link to comment
Share on other sites

Guest
This topic is now closed to further replies.
 Share

×
×
  • Create New...