matthias_klose fastjar 0.98 directory traversal vulnerabilities

2010-06-21 / 2010-06-22
Credit: Vincent Danen
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-22


CVSS Base Score: 2.6/10
Impact Subscore: 2.9/10
Exploitability Subscore: 4.9/10
Exploit range: Remote
Attack complexity: High
Authentication: No required
Confidentiality impact: None
Integrity impact: Partial
Availability impact: None

A directory traversal flaw was reported in fastjar that was assigned CVE-2010-0831. Upon investigation, it was found that the jar program ] had a similar problem. No CVE name was assigned to the jar issue, however it looks like they are two different programs with two different code bases. There is also some confusion because these issues are similar to (or a result of incomplete fixes for) CVE-2006-3619 (fastjar) and CVE-2005-1080 (jar). What makes things worse is that it doesn't look like CVE-2005-1080 was ever fixed. So I'm not sure if this "new" jar issue needs a new CVE name, or if it would be covered under CVE-2005-1080 (since nothing ever claimed to fix this directory traversal vulnerability in jar). Any insight from MITRE would be appreciated. I've not assigned a CVE name to the "new" jar issue because of this confusion.

References:

https://launchpad.net/bugs/540575
https://bugzilla.redhat.com/show_bug.cgi?id=601823
https://bugzilla.redhat.com/show_bug.cgi?id=594497
http://www.osvdb.org/65467
http://packages.debian.org/changelogs/pool/main/f/fastjar/fastjar_0.98-3/changelog
http://marc.info/?l=oss-security&m=127602564508766&w=2


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top