Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Sdk | Sun | 1.4.2 (including) | 1.4.2 (including) |
Sdk | Sun | 1.5 (including) | 1.5 (including) |
Oracle Java for Red Hat Enterprise Linux 5 | RedHat | java-1.7.0-oracle-1:1.7.0.79-1jpp.1.el5_11 | * |
Oracle Java for Red Hat Enterprise Linux 5 | RedHat | java-1.6.0-sun-1:1.6.0.95-1jpp.3.el5_11 | * |
Oracle Java for Red Hat Enterprise Linux 6 | RedHat | java-1.8.0-oracle-1:1.8.0.45-1jpp.2.el6_6 | * |
Oracle Java for Red Hat Enterprise Linux 6 | RedHat | java-1.7.0-oracle-1:1.7.0.79-1jpp.1.el6_6 | * |
Oracle Java for Red Hat Enterprise Linux 6 | RedHat | java-1.6.0-sun-1:1.6.0.95-1jpp.3.el6_6 | * |
Oracle Java for Red Hat Enterprise Linux 7 | RedHat | java-1.8.0-oracle-1:1.8.0.45-1jpp.2.el7_1 | * |
Oracle Java for Red Hat Enterprise Linux 7 | RedHat | java-1.7.0-oracle-1:1.7.0.79-1jpp.1.el7_1 | * |
Oracle Java for Red Hat Enterprise Linux 7 | RedHat | java-1.6.0-sun-1:1.6.0.95-1jpp.3.el7_1 | * |
Red Hat Enterprise Linux 5 | RedHat | java-1.7.0-openjdk-1:1.7.0.79-2.5.5.2.el5_11 | * |
Red Hat Enterprise Linux 5 | RedHat | java-1.6.0-openjdk-1:1.6.0.35-1.13.7.1.el5_11 | * |
Red Hat Enterprise Linux 5 Supplementary | RedHat | java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el5 | * |
Red Hat Enterprise Linux 5 Supplementary | RedHat | java-1.7.0-ibm-1:1.7.0.9.0-1jpp.1.el5 | * |
Red Hat Enterprise Linux 5 Supplementary | RedHat | java-1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el5 | * |
Red Hat Enterprise Linux 6 | RedHat | java-1.7.0-openjdk-1:1.7.0.79-2.5.5.1.el6_6 | * |
Red Hat Enterprise Linux 6 | RedHat | java-1.6.0-openjdk-1:1.6.0.35-1.13.7.1.el6_6 | * |
Red Hat Enterprise Linux 6 | RedHat | java-1.8.0-openjdk-1:1.8.0.45-28.b13.el6_6 | * |
Red Hat Enterprise Linux 7 | RedHat | java-1.7.0-openjdk-1:1.7.0.79-2.5.5.1.ael7b_1 | * |
Red Hat Enterprise Linux 7 | RedHat | java-1.6.0-openjdk-1:1.6.0.35-1.13.7.1.el7_1 | * |
Red Hat Enterprise Linux 7 | RedHat | java-1.8.0-openjdk-1:1.8.0.45-30.b13.el7_1 | * |
Red Hat Satellite 5.6 | RedHat | java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6 | * |
Red Hat Satellite 5.7 | RedHat | java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6 | * |
Supplementary for Red Hat Enterprise Linux 6 | RedHat | java-1.6.0-ibm-1:1.6.0.16.4-1jpp.1.el6_6 | * |
Supplementary for Red Hat Enterprise Linux 6 | RedHat | java-1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el6_6 | * |
Supplementary for Red Hat Enterprise Linux 6 | RedHat | java-1.5.0-ibm-1:1.5.0.16.10-1jpp.1.el6_6 | * |
Supplementary for Red Hat Enterprise Linux 7 | RedHat | java-1.7.1-ibm-1:1.7.1.3.0-1jpp.2.el7_1 | * |
Openjdk-6 | Ubuntu | hardy | * |
Openjdk-6 | Ubuntu | jaunty | * |
Openjdk-6 | Ubuntu | karmic | * |
Openjdk-6 | Ubuntu | lucid | * |
Openjdk-6 | Ubuntu | maverick | * |
Openjdk-6 | Ubuntu | natty | * |
Openjdk-6 | Ubuntu | oneiric | * |
Openjdk-6 | Ubuntu | precise | * |
Openjdk-6 | Ubuntu | quantal | * |
Openjdk-6 | Ubuntu | raring | * |
Openjdk-6 | Ubuntu | saucy | * |
Openjdk-6 | Ubuntu | trusty | * |
Openjdk-6 | Ubuntu | utopic | * |
Openjdk-6 | Ubuntu | wily | * |
Sun-java5 | Ubuntu | dapper | * |
Sun-java5 | Ubuntu | hardy | * |
Sun-java5 | Ubuntu | intrepid | * |
Sun-java5 | Ubuntu | jaunty | * |
Sun-java6 | Ubuntu | hardy | * |
Sun-java6 | Ubuntu | intrepid | * |
Sun-java6 | Ubuntu | jaunty | * |
Sun-java6 | Ubuntu | karmic | * |