Dan Rosenberg reported a directory traversal flaw in fastjar that allows an attacker, who is able to convince a victim to extract a malicious .jar file, to overwrite arbitrary files on disk without prompting the victim. The files to be overwritten must be writable by the user extracting the .jar file.
This issue has been assigned the name CVE-2010-0831, and it is possible that it is due to an incomplete fix for CVE-2006-3619 (bug #198912).
Upon investigation, the same problem exists in the jar archiver as provided by OpenJDK and java-1.4.2-gcj-compat.