CVE-2010-2322: Path Traversal
Absolute path traversal vulnerability in the extractjar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a full pathname for a file within a .jar archive, a related issue to CVE-2010-0831. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2322?
CVE-2010-2322 is considered a moderate severity vulnerability due to its potential to allow unauthorized file creation or overwriting.
How do I fix CVE-2010-2322?
To fix CVE-2010-2322, you should update FastJar to a version that patches this vulnerability.
What impact does CVE-2010-2322 have on my system?
The impact of CVE-2010-2322 allows remote attackers to manipulate files on the server, potentially compromising sensitive data or system integrity.
Is CVE-2010-2322 exploitable remotely?
Yes, CVE-2010-2322 can be exploited remotely, allowing attackers to craft malicious .jar files.
Which versions of FastJar are affected by CVE-2010-2322?
FastJar version 0.98 is affected by CVE-2010-2322.