USN-953-1: fastjar vulnerability
21 June 2010
Releases
Packages
- fastjar -
Details
Dan Rosenberg discovered that fastjar incorrectly handled file paths
containing ".." when unpacking archives. If a user or an automated system
were tricked into unpacking a specially crafted jar file, arbitrary files
could be overwritten with user privileges.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 9.10
Ubuntu 9.04
Ubuntu 8.04
Ubuntu 10.04
In general, a standard system update will make all the necessary changes.