Описание
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | DNE | |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was released [6b35-1.13.7-1ubuntu0.14.04.1 ]] |
hardy | ignored | end of life |
jaunty | ignored | end of life |
karmic | ignored | end of life |
lucid | released | 6b35-1.13.7-1ubuntu0.10.04.2 |
maverick | ignored | end of life |
natty | ignored | end of life |
oneiric | ignored | end of life |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | ignored | end of life |
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
hardy | ignored | end of life |
intrepid | ignored | end of life |
jaunty | ignored | end of life |
karmic | DNE | |
lucid | DNE | |
maverick | DNE | |
natty | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
dapper | DNE | |
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
hardy | ignored | end of life |
intrepid | ignored | end of life |
jaunty | ignored | end of life |
karmic | ignored | end of life |
lucid | DNE | removed from archive |
maverick | DNE | removed from archive |
natty | DNE | removed from archive |
Показывать по
EPSS
5 Medium
CVSS2
Связанные уязвимости
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
ELSA-2015-0808: java-1.6.0-openjdk security update (IMPORTANT)
ELSA-2015-0807: java-1.7.0-openjdk security update (IMPORTANT)
EPSS
5 Medium
CVSS2