fastjar: Directory traversal
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201209-21 / fastjar |
| Release Date |
September 28, 2012 |
| Latest Revision |
September 28, 2012: 1 |
| Impact |
normal |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| app-arch/fastjar |
<
0.98-r1 |
>=
0.98-r1 |
All supported architectures
|
Related bugreports:
#325557
Synopsis
Two directory traversal vulnerabilities have been found in fastjar,
allowing remote attackers to create or overwrite arbitrary files.
2.
Impact Information
Background
fastjar is a Java archiver written in C.
Description
Two directory traversal vulnerabilities have been discovered in fastjar.
Please review the CVE identifiers referenced below for details.
Impact
A remote attacker could entice a user to open a specially crafted JAR
file, possibly resulting in the creation or truncation of arbitrary
files.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All fastjar users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-arch/fastjar-0.98-r1"
|
4.
References
|