FastJar 'extract_jar()' Absolute Path Archive Extraction Directory Traversal Vulnerability
BID:41009
Info
FastJar 'extract_jar()' Absolute Path Archive Extraction Directory Traversal Vulnerability
| Bugtraq ID: | 41009 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-2322 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 08 2010 12:00AM |
| Updated: | Apr 13 2015 09:59PM |
| Credit: | Dan Rosenberg |
| Vulnerable: |
Redhat Enterprise Linux Desktop Workstation 5 client Redhat Enterprise Linux Desktop 5 client Redhat Enterprise Linux 5 Server Gentoo Linux FastJar FastJar 0.93 FastJar FastJar 0.98 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Avaya Voice Portal 5.1.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.1 Avaya Voice Portal 5.0 SP2 Avaya Voice Portal 5.0 SP1 Avaya Voice Portal 5.0 Avaya IQ 5.1 Avaya IQ 5 Avaya Conferencing Standard Edition 6.0.1 Avaya Communication Server 1000M Signaling Server 7.5 Avaya Communication Server 1000M Signaling Server 7.0 Avaya Communication Server 1000M Signaling Server 6.0 Avaya Communication Server 1000M 7.5 Avaya Communication Server 1000M 7.0 Avaya Communication Server 1000M 6.0 Avaya Communication Server 1000E Signaling Server 7.5 Avaya Communication Server 1000E Signaling Server 7.0 Avaya Communication Server 1000E Signaling Server 6.0 Avaya Communication Server 1000E 7.5 Avaya Communication Server 1000E 7.0 Avaya Communication Server 1000E 6.0 Avaya Aura System Platform 6.0 Avaya Aura System Platform 1.0 Avaya Aura System Manager 6.1.3 Avaya Aura System Manager 6.1.2 Avaya Aura System Manager 6.1.1 Avaya Aura System Manager 6.1 Avaya Aura System Manager 6.0 SP1 Avaya Aura System Manager 6.0 Avaya Aura System Manager 5.2 Avaya Aura Session Manager 6.1 Avaya Aura Session Manager 6.0 SP1 Avaya Aura Session Manager 6.0 Avaya Aura Session Manager 5.2 SP2 Avaya Aura Session Manager 5.2 SP1 Avaya Aura Session Manager 5.2 Avaya Aura Session Manager 1.1 Avaya Aura Presence Services 6.1 Avaya Aura Presence Services 6.0 Avaya Aura Conferencing 6.0 Standard Avaya Aura Conferencing 6.0 SP1 Standard Avaya Aura Application Server 2.1 Avaya Aura Application Server 2.0 Avaya Aura Application Enablement Services 5.2.1 Avaya Aura Application Enablement Services 6.1 Avaya Aura Application Enablement Services 5.2 |
| Not Vulnerable: | |
Discussion
FastJar 'extract_jar()' Absolute Path Archive Extraction Directory Traversal Vulnerability
FastJar is prone to a directory-traversal vulnerability because the utility fails to properly sanitize user-supplied data.
An attacker can exploit this vulnerability to overwrite arbitrary files in the context of the user running the vulnerable application. Depending on the files overwritten, this could cause the system to crash or could facilitate unauthorized access; other attacks are also possible.
NOTE: This issue is due to an incomplete fix for the vulnerability described in BID 15669 (Fastjar Archive Extraction Directory Traversal Vulnerability).
FastJar is prone to a directory-traversal vulnerability because the utility fails to properly sanitize user-supplied data.
An attacker can exploit this vulnerability to overwrite arbitrary files in the context of the user running the vulnerable application. Depending on the files overwritten, this could cause the system to crash or could facilitate unauthorized access; other attacks are also possible.
NOTE: This issue is due to an incomplete fix for the vulnerability described in BID 15669 (Fastjar Archive Extraction Directory Traversal Vulnerability).
Exploit / POC
FastJar 'extract_jar()' Absolute Path Archive Extraction Directory Traversal Vulnerability
Attackers must trick a victim into opening a malicious archive to exploit this issue.
Attackers must trick a victim into opening a malicious archive to exploit this issue.
Solution / Fix
FastJar 'extract_jar()' Absolute Path Archive Extraction Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
FastJar 'extract_jar()' Absolute Path Archive Extraction Directory Traversal Vulnerability
References:
References:
- [oss-security] jar, fastjar directory traversal vulnerabilities (Vincent Danen)
- Bug 594497 - (CVE-2010-0831, CVE-2010-2322) CVE-2010-0831 CVE-2010-2322 fastjar: (Red Hat)
- Debian Changelog fastjar (2:0.98-3) (Debian)
- FastJar Homepage (FastJar)
- ASA-2011-056 gcc security and bug fix update (RHSA-2011-0025) (Avaya)