Summary
Ubuntu Update for Linux kernel vulnerabilities USN-953-1
Solution
Please Install the Updated Packages.
Insight
Dan Rosenberg discovered that fastjar incorrectly handled file paths containing "
.."
when unpacking archives. If a user or an automated system were tricked into unpacking a specially crafted jar file, arbitrary files could be overwritten with user privileges.
Affected
fastjar vulnerability on Ubuntu 8.04 LTS ,
Ubuntu 9.04 ,
Ubuntu 9.10 ,
Ubuntu 10.04 LTS
Severity
Classification
-
CVE CVE-2010-0831 -
CVSS Base Score: 5.8
AV:N/AC:M/Au:N/C:N/I:P/A:P
Related Vulnerabilities