First published: Tue Jan 04 2005(Updated: )
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/IcedTea6 | <1.13.7 | 1.13.7 |
redhat/IcedTea7 | <2.5.5 | 2.5.5 |
redhat/java | <1.7.0-oracle-1:1.7.0.79-1jpp.1.el5_11 | 1.7.0-oracle-1:1.7.0.79-1jpp.1.el5_11 |
redhat/java | <1.6.0-sun-1:1.6.0.95-1jpp.3.el5_11 | 1.6.0-sun-1:1.6.0.95-1jpp.3.el5_11 |
redhat/java | <1.8.0-oracle-1:1.8.0.45-1jpp.2.el6_6 | 1.8.0-oracle-1:1.8.0.45-1jpp.2.el6_6 |
redhat/java | <1.7.0-oracle-1:1.7.0.79-1jpp.1.el6_6 | 1.7.0-oracle-1:1.7.0.79-1jpp.1.el6_6 |
redhat/java | <1.6.0-sun-1:1.6.0.95-1jpp.3.el6_6 | 1.6.0-sun-1:1.6.0.95-1jpp.3.el6_6 |
redhat/java | <1.8.0-oracle-1:1.8.0.45-1jpp.2.el7_1 | 1.8.0-oracle-1:1.8.0.45-1jpp.2.el7_1 |
redhat/java | <1.7.0-oracle-1:1.7.0.79-1jpp.1.el7_1 | 1.7.0-oracle-1:1.7.0.79-1jpp.1.el7_1 |
redhat/java | <1.6.0-sun-1:1.6.0.95-1jpp.3.el7_1 | 1.6.0-sun-1:1.6.0.95-1jpp.3.el7_1 |
redhat/java | <1.7.0-openjdk-1:1.7.0.79-2.5.5.2.el5_11 | 1.7.0-openjdk-1:1.7.0.79-2.5.5.2.el5_11 |
redhat/java | <1.6.0-openjdk-1:1.6.0.35-1.13.7.1.el5_11 | 1.6.0-openjdk-1:1.6.0.35-1.13.7.1.el5_11 |
redhat/java | <1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5 | 1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5 |
redhat/java | <1.7.0-ibm-1:1.7.0.9.0-1jpp.1.el5 | 1.7.0-ibm-1:1.7.0.9.0-1jpp.1.el5 |
redhat/java | <1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el5 | 1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el5 |
redhat/java | <1.7.0-openjdk-1:1.7.0.79-2.5.5.1.el6_6 | 1.7.0-openjdk-1:1.7.0.79-2.5.5.1.el6_6 |
redhat/java | <1.6.0-openjdk-1:1.6.0.35-1.13.7.1.el6_6 | 1.6.0-openjdk-1:1.6.0.35-1.13.7.1.el6_6 |
redhat/java | <1.8.0-openjdk-1:1.8.0.45-28.b13.el6_6 | 1.8.0-openjdk-1:1.8.0.45-28.b13.el6_6 |
redhat/java | <1.7.0-openjdk-1:1.7.0.79-2.5.5.1.ael7b | 1.7.0-openjdk-1:1.7.0.79-2.5.5.1.ael7b |
redhat/java | <1.6.0-openjdk-1:1.6.0.35-1.13.7.1.el7_1 | 1.6.0-openjdk-1:1.6.0.35-1.13.7.1.el7_1 |
redhat/java | <1.8.0-openjdk-1:1.8.0.45-30.b13.ael7b | 1.8.0-openjdk-1:1.8.0.45-30.b13.ael7b |
redhat/java | <1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6 | 1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6 |
redhat/java | <1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el6_6 | 1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el6_6 |
redhat/java | <1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el6_6 | 1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el6_6 |
redhat/java | <1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el7_1 | 1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el7_1 |
Java Development Kit (JDK) | =1.5 | |
Java Development Kit (JDK) | =1.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2005-1080 is classified as a high severity vulnerability due to its potential for remote exploitation.
To fix CVE-2005-1080, update to the latest version of Java that resolves this vulnerability.
CVE-2005-1080 affects J2SE SDK versions 1.4.2 and 1.5.
Yes, CVE-2005-1080 allows remote attackers to create or overwrite arbitrary files, leading to unauthorized access.
Yes, OpenJDK is also vulnerable to CVE-2005-1080, similar to affected versions of the J2SE SDK.