Bug 818591 (CVE-2010-0831) - VUL-1: CVE-2010-0831: fastjar: directory traversal
Summary: VUL-1: CVE-2010-0831: fastjar: directory traversal
Status: RESOLVED FIXED
Alias: CVE-2010-0831
Product: SUSE Security Incidents
Classification: Novell Products
Component: General (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: . CVSSv2:NVD:CVE-2010-0831:5.8:(AV:N/...
Keywords:
Depends on:
Blocks:
 
Reported: 2013-05-06 12:45 UTC by Marcus Meissner
Modified: 2019-05-01 15:21 UTC (History)
5 users (show)

See Also:
Found By: Development
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Marcus Meissner 2013-05-06 12:46:52 UTC
Date: Tue, 8 Jun 2010 13:33:35 -0600
From: Vincent Danen <vdanen@redhat.com>
To: oss-security@lists.openwall.com
Cc: "Steven M. Christey" <coley@linus.mitre.org>
Subject: [oss-security] jar, fastjar directory traversal vulnerabilities


Hi all.

A directory traversal flaw was reported in fastjar [1] that was assigned
CVE-2010-0831.  Upon investigation, it was found that the jar program
[2] had a similar problem.  No CVE name was assigned to the jar issue,
however it looks like they are two different programs with two different
code bases.

There is also some confusion because these issues are similar to (or a
result of incomplete fixes for) CVE-2006-3619 (fastjar) and
CVE-2005-1080 (jar).

What makes things worse is that it doesn't look like CVE-2005-1080 was
ever fixed.  So I'm not sure if this "new" jar issue needs a new CVE
name, or if it would be covered under CVE-2005-1080 (since nothing ever
claimed to fix this directory traversal vulnerability in jar).

Any insight from MITRE would be appreciated.  I've not assigned a CVE
name to the "new" jar issue because of this confusion.
Comment 2 Marcus Meissner 2013-05-06 12:49:48 UTC
patch is already in openSUSE 12.1 and later, but not in SLE11.
Comment 3 Swamp Workflow Management 2013-05-06 22:00:10 UTC
bugbot adjusting priority
Comment 9 Johannes Segitz 2015-02-04 08:49:15 UTC
your right, I removed the bug from the planned updates