FastJar 'extract_jar()' Archive Extraction Directory Traversal Vulnerability
BID:41006
Info
FastJar 'extract_jar()' Archive Extraction Directory Traversal Vulnerability
| Bugtraq ID: | 41006 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-0831 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2010 12:00AM |
| Updated: | Apr 13 2015 09:43PM |
| Credit: | Dan Rosenberg |
| Vulnerable: |
Ubuntu Ubuntu Linux 9.10 sparc Ubuntu Ubuntu Linux 9.10 powerpc Ubuntu Ubuntu Linux 9.10 lpia Ubuntu Ubuntu Linux 9.10 i386 Ubuntu Ubuntu Linux 9.10 amd64 Ubuntu Ubuntu Linux 9.04 sparc Ubuntu Ubuntu Linux 9.04 powerpc Ubuntu Ubuntu Linux 9.04 lpia Ubuntu Ubuntu Linux 9.04 i386 Ubuntu Ubuntu Linux 9.04 amd64 Ubuntu Ubuntu Linux 8.04 LTS sparc Ubuntu Ubuntu Linux 8.04 LTS powerpc Ubuntu Ubuntu Linux 8.04 LTS lpia Ubuntu Ubuntu Linux 8.04 LTS i386 Ubuntu Ubuntu Linux 8.04 LTS amd64 Ubuntu Ubuntu Linux 10.04 sparc Ubuntu Ubuntu Linux 10.04 powerpc Ubuntu Ubuntu Linux 10.04 i386 Ubuntu Ubuntu Linux 10.04 amd64 Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Mandriva Linux Mandrake 2010.0 x86_64 Mandriva Linux Mandrake 2010.0 Mandriva Linux Mandrake 2009.1 x86_64 Mandriva Linux Mandrake 2009.1 Mandriva Linux Mandrake 2009.0 x86_64 Mandriva Linux Mandrake 2009.0 Mandriva Linux Mandrake 2008.0 x86_64 Mandriva Linux Mandrake 2008.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 4.0 Gentoo Linux FastJar FastJar 0.93 FastJar FastJar 0.98 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya IQ 5.1 Avaya IQ 5 Avaya Conferencing Standard Edition 6.0.1 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.0 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Application Server 2.1 Avaya Aura Application Server 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: | |
Discussion
FastJar 'extract_jar()' Archive Extraction Directory Traversal Vulnerability
FastJar is prone to a directory-traversal vulnerability because the utility fails to properly sanitize user-supplied data.
An attacker can exploit this vulnerability to overwrite arbitrary files in the context of the user running the vulnerable application. Depending on the files overwritten, this could cause the system to crash or could facilitate unauthorized access; other attacks are also possible.
NOTE: This issue is due to an incomplete fix for the vulnerability described in BID 15669 (Fastjar Archive Extraction Directory Traversal Vulnerability).
FastJar is prone to a directory-traversal vulnerability because the utility fails to properly sanitize user-supplied data.
An attacker can exploit this vulnerability to overwrite arbitrary files in the context of the user running the vulnerable application. Depending on the files overwritten, this could cause the system to crash or could facilitate unauthorized access; other attacks are also possible.
NOTE: This issue is due to an incomplete fix for the vulnerability described in BID 15669 (Fastjar Archive Extraction Directory Traversal Vulnerability).
Exploit / POC
FastJar 'extract_jar()' Archive Extraction Directory Traversal Vulnerability
Attackers must trick a victim into opening a malicious archive to exploit this issue.
Attackers must trick a victim into opening a malicious archive to exploit this issue.
Solution / Fix
FastJar 'extract_jar()' Archive Extraction Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 9.10 sparc
Ubuntu Ubuntu Linux 8.04 LTS powerpc
Ubuntu Ubuntu Linux 8.04 LTS sparc
Ubuntu Ubuntu Linux 9.10 powerpc
Mandriva Linux Mandrake 2008.0 x86_64
Ubuntu Ubuntu Linux 8.04 LTS amd64
Mandriva Linux Mandrake 2008.0
Ubuntu Ubuntu Linux 9.10 lpia
Ubuntu Ubuntu Linux 9.04 sparc
Mandriva Linux Mandrake 2010.0
Ubuntu Ubuntu Linux 9.04 powerpc
Ubuntu Ubuntu Linux 10.04 powerpc
Ubuntu Ubuntu Linux 9.04 i386
Ubuntu Ubuntu Linux 9.04 lpia
Ubuntu Ubuntu Linux 9.10 i386
Ubuntu Ubuntu Linux 10.04 amd64
Ubuntu Ubuntu Linux 9.10 amd64
Mandriva Linux Mandrake 2009.0 x86_64
Ubuntu Ubuntu Linux 9.04 amd64
Mandriva Linux Mandrake 2009.1
Ubuntu Ubuntu Linux 10.04 i386
Mandriva Linux Mandrake 2009.1 x86_64
Ubuntu Ubuntu Linux 8.04 LTS lpia
Mandriva Linux Mandrake 2010.0 x86_64
Mandriva Linux Mandrake 2009.0
Solution:
Updates are available. Please see the references for more information.
Ubuntu Ubuntu Linux 9.10 sparc
-
Ubuntu fastjar_0.98-1ubuntu0.9.10.1_sparc.deb
http://ports.ubuntu.com/pool/main/f/fastjar/fastjar_0.98-1ubuntu0.9.10 .1_sparc.deb
Ubuntu Ubuntu Linux 8.04 LTS powerpc
-
Ubuntu fastjar_0.95-1ubuntu2.1_powerpc.deb
http://ports.ubuntu.com/pool/main/f/fastjar/fastjar_0.95-1ubuntu2.1_po werpc.deb
Ubuntu Ubuntu Linux 8.04 LTS sparc
-
Ubuntu fastjar_0.95-1ubuntu2.1_sparc.deb
http://ports.ubuntu.com/pool/main/f/fastjar/fastjar_0.95-1ubuntu2.1_sp arc.deb
Ubuntu Ubuntu Linux 9.10 powerpc
-
Ubuntu fastjar_0.98-1ubuntu0.9.10.1_powerpc.deb
http://ports.ubuntu.com/pool/main/f/fastjar/fastjar_0.98-1ubuntu0.9.10 .1_powerpc.deb
Mandriva Linux Mandrake 2008.0 x86_64
-
Mandriva fastjar-0.95-1.1mdv2008.0.x86_64.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.04 LTS amd64
-
Ubuntu fastjar_0.95-1ubuntu2.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/f/fastjar/fastjar_0.95-1ub untu2.1_amd64.deb
Mandriva Linux Mandrake 2008.0
-
Mandriva fastjar-0.95-1.1mdv2008.0.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 9.10 lpia
-
Ubuntu fastjar_0.98-1ubuntu0.9.10.1_lpia.deb
http://ports.ubuntu.com/pool/main/f/fastjar/fastjar_0.98-1ubuntu0.9.10 .1_lpia.deb
Ubuntu Ubuntu Linux 9.04 sparc
-
Ubuntu fastjar_0.97-3ubuntu0.1_sparc.deb
http://ports.ubuntu.com/pool/main/f/fastjar/fastjar_0.97-3ubuntu0.1_sp arc.deb
Mandriva Linux Mandrake 2010.0
-
Mandriva fastjar-0.98-1.1mdv2010.0.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 9.04 powerpc
-
Ubuntu fastjar_0.97-3ubuntu0.1_powerpc.deb
http://ports.ubuntu.com/pool/main/f/fastjar/fastjar_0.97-3ubuntu0.1_po werpc.deb
Ubuntu Ubuntu Linux 10.04 powerpc
-
Ubuntu fastjar_0.98-1ubuntu0.10.04.1_powerpc.deb
http://ports.ubuntu.com/pool/main/f/fastjar/fastjar_0.98-1ubuntu0.10.0 4.1_powerpc.deb
Ubuntu Ubuntu Linux 9.04 i386
-
Ubuntu fastjar_0.97-3ubuntu0.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/f/fastjar/fastjar_0.97-3ub untu0.1_i386.deb
Ubuntu Ubuntu Linux 9.04 lpia
-
Ubuntu fastjar_0.97-3ubuntu0.1_lpia.deb
http://ports.ubuntu.com/pool/main/f/fastjar/fastjar_0.97-3ubuntu0.1_lp ia.deb
Ubuntu Ubuntu Linux 9.10 i386
-
Ubuntu fastjar_0.98-1ubuntu0.9.10.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/f/fastjar/fastjar_0.98-1ub untu0.9.10.1_i386.deb
Ubuntu Ubuntu Linux 10.04 amd64
-
Ubuntu fastjar_0.98-1ubuntu0.10.04.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/f/fastjar/fastjar_0.98-1ub untu0.10.04.1_amd64.deb
Ubuntu Ubuntu Linux 9.10 amd64
-
Ubuntu fastjar_0.98-1ubuntu0.9.10.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/f/fastjar/fastjar_0.98-1ub untu0.9.10.1_amd64.deb
Mandriva Linux Mandrake 2009.0 x86_64
-
Mandriva fastjar-0.95-3.1mdv2009.0.x86_64.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 9.04 amd64
-
Ubuntu fastjar_0.97-3ubuntu0.1_amd64.deb
http://security.ubuntu.com/ubuntu/pool/main/f/fastjar/fastjar_0.97-3ub untu0.1_amd64.deb
Mandriva Linux Mandrake 2009.1
-
Mandriva fastjar-0.97-1.1mdv2009.1.i586.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 10.04 i386
-
Ubuntu fastjar_0.98-1ubuntu0.10.04.1_i386.deb
http://security.ubuntu.com/ubuntu/pool/main/f/fastjar/fastjar_0.98-1ub untu0.10.04.1_i386.deb
Mandriva Linux Mandrake 2009.1 x86_64
-
Mandriva fastjar-0.97-1.1mdv2009.1.x86_64.rpm
http://www.mandriva.com/en/download/
Ubuntu Ubuntu Linux 8.04 LTS lpia
-
Ubuntu fastjar_0.95-1ubuntu2.1_lpia.deb
http://ports.ubuntu.com/pool/main/f/fastjar/fastjar_0.95-1ubuntu2.1_lp ia.deb
Mandriva Linux Mandrake 2010.0 x86_64
-
Mandriva fastjar-0.98-1.1mdv2010.0.x86_64.rpm
http://www.mandriva.com/en/download/
Mandriva Linux Mandrake 2009.0
-
Mandriva fastjar-0.95-3.1mdv2009.0.i586.rpm
http://www.mandriva.com/en/download/
References
FastJar 'extract_jar()' Archive Extraction Directory Traversal Vulnerability
References:
References:
- [oss-security] jar, fastjar directory traversal vulnerabilities (Vincent Danen)
- Bug 594497 - (CVE-2010-0831, CVE-2010-2322) CVE-2010-0831 CVE-2010-2322 fastjar: (Red Hat)
- Bug 601823 - CVE-2010-0831 jar, fastjar: directory traversal vulnerabilities [fe (Red Hat)
- Debian Changelog fastjar (2:0.98-3) (Debian)
- FastJar Homepage (FastJar)
- ASA-2011-056 gcc security and bug fix update (RHSA-2011-0025) (Avaya)