REDHAT-BUG-594497: Low severity red hat fastjar vulnerability
Dan Rosenberg reported a directory traversal flaw in fastjar that allows an attacker, who is able to convince a victim to extract a malicious .jar file, to overwrite arbitrary files on disk without prompting the victim. The files to be overwritten must be writable by the user extracting the .jar file.
This issue has been assigned the name CVE-2010-0831, and it is possible that it is due to an incomplete fix for CVE-2006-3619 (bug #198912).
Upon investigation, the same problem exists in the jar archiver as provided by OpenJDK and java-1.4.2-gcj-compat.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-594497?
REDHAT-BUG-594497 has a high severity rating due to the potential for arbitrary file overwriting without user consent.
How do I fix REDHAT-BUG-594497?
To fix REDHAT-BUG-594497, update the fastjar and OpenJDK packages to their latest versions where the vulnerability is patched.
What systems are affected by REDHAT-BUG-594497?
Systems running Red Hat fastjar and Oracle OpenJDK are affected by REDHAT-BUG-594497.
What type of vulnerability is REDHAT-BUG-594497?
REDHAT-BUG-594497 is a directory traversal vulnerability that allows file overwriting.
Who reported the vulnerability REDHAT-BUG-594497?
The directory traversal flaw in fastjar was reported by Dan Rosenberg.