CVE-2005-1080
published 2005-05-02CVE-2005-1080: Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite…
PriorityP430medium5CVSS 2.0
AVNACLAuNCNIPAN
EPSS
6.72%
93.2th percentile
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fastjar | < fastjar 2:0.98-3 (bookworm) | fastjar 2:0.98-3 (bookworm) |
| fastjar | fastjar | >= 0 < 2:0.98-3 | 2:0.98-3 |
| fastjar | fastjar | >= 0 < 2:0.98-3 | 2:0.98-3 |
| fastjar | fastjar | >= 0 < 2:0.98-3 | 2:0.98-3 |
| fastjar | fastjar | >= 0 < 2:0.98-3 | 2:0.98-3 |
| matthias_klose | fastjar | — | — |
| sun | sdk | — | — |
| sun | sdk | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fcqq-mm95-6mqp: Directory traversal vulnerability in the extract_jar function in jartool
ghsa_unreviewed·2022-05-02·CVSS 5.0
CVE-2010-0831 [MEDIUM] CWE-22 GHSA-fcqq-mm95-6mqp: Directory traversal vulnerability in the extract_jar function in jartool
Directory traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a non-initial pathname component in a filename within a .jar archive, a related issue to CVE-2005-1080. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.
GHSA
GHSA-g7vc-f4x5-69xx: Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1
ghsa_unreviewed·2022-05-01
CVE-2005-1080 [MEDIUM] GHSA-g7vc-f4x5-69xx: Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
OSV
CVE-2010-0831: Directory traversal vulnerability in the extract_jar function in jartool
osv·2010-06-18·CVSS 5.0
CVE-2010-0831 [MEDIUM] CVE-2010-0831: Directory traversal vulnerability in the extract_jar function in jartool
Directory traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a non-initial pathname component in a filename within a .jar archive, a related issue to CVE-2005-1080. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.
OSV
CVE-2005-1080: Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1
osv·2005-05-02·CVSS 5.0
CVE-2005-1080 [MEDIUM] CVE-2005-1080: Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
Red Hat
fastjar: directory traversal vulnerabilities
vendor_redhat·2010-06-06·CVSS 5.0
CVE-2010-0831 [MEDIUM] fastjar: directory traversal vulnerabilities
fastjar: directory traversal vulnerabilities
Directory traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a non-initial pathname component in a filename within a .jar archive, a related issue to CVE-2005-1080. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact, a future update may address this flaw.
Package: gcc (Red Hat Enterprise Linux 4) - Will not fix
Package: gcc4 (Red Hat Enterprise Linux 4) - Will not fix
Package: gcc44 (Red Hat Enterprise Linux 5) - Not affected
Package: gcc (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2010-0831: fastjar - Directory traversal vulnerability in the extract_jar function in jartool.c in Fa...
vendor_debian·2010·CVSS 5.0
CVE-2010-0831 [MEDIUM] CVE-2010-0831: fastjar - Directory traversal vulnerability in the extract_jar function in jartool.c in Fa...
Directory traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a non-initial pathname component in a filename within a .jar archive, a related issue to CVE-2005-1080. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.
Scope: local
bookworm: resolved (fixed in 2:0.98-3)
bullseye: resolved (fixed in 2:0.98-3)
forky: resolved (fixed in 2:0.98-3)
sid: resolved (fixed in 2:0.98-3)
trixie: resolved (fixed in 2:0.98-3)
Red Hat
jar: directory traversal vulnerability
vendor_redhat·2005-01-04·CVSS 5.0
CVE-2005-1080 [MEDIUM] CWE-22 jar: directory traversal vulnerability
jar: directory traversal vulnerability
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
A directory traversal flaw was found in the way the jar tool extracted JAR archive files. A specially crafted JAR archive could cause jar to overwrite arbitrary files writable by the user running jar when the archive was extracted.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-0480 OpenJDK: jar directory traversal issues (Tools, 8064601)
bugzilla·2015-04-14·CVSS 5.0
CVE-2015-0480 [MEDIUM] CVE-2015-0480 OpenJDK: jar directory traversal issues (Tools, 8064601)
CVE-2015-0480 OpenJDK: jar directory traversal issues (Tools, 8064601)
A directory traversal flaw was found in jar, The Java Archive Tool. Relative paths containing '..' or absolute paths used for files stored in a specially-crafted jar archive could cause the jar tool to overwrite arbitrary files when the archive was extracted.
With this update, jar strips leading '/' or path prefix that contains '..'. New command line option -P can be used to revert back to the old insecure behavior which preserves absolute paths and paths with '..'.
This issue was reported multiple times in the past and already got CVE-2005-1080 (bug 606442) assigned. This CVE is a duplicate of the old 2005 id.
Discussion:
Public now via Oracle Critical Patch Update - April 2015. Fixed in Oracle Java SE 6u95, 7u79,
Bugzilla
jar: directory traversal
bugzilla·2015-01-09·CVSS 5.0
CVE-2005-1080 [MEDIUM] jar: directory traversal
jar: directory traversal
It was reported [1] that jar(1) is susceptible to a directory traversal vulnerability. While extracting an archive, it will happily use absolute and relative paths taken from the archive. This can be exploited by a malicious archive to write files outside the current directory.
This issue might be relevant to the (incomplete) fix of CVE-2005-1080. Please note that CVE-2005-1080 talks about .. only.
[1]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774953
Discussion:
Created java-1.7.0-openjdk tracking bugs for this issue:
Affects: fedora-all [bug 1180591]
---
Created java-1.8.0-openjdk tracking bugs for this issue:
Affects: fedora-all [bug 1180593]
---
Marking this as duplicate of CVE-2005-1080.
*** This bug has been marked as a duplicate of bug 60
Bugzilla
CVE-2005-1080 jar: directory traversal vulnerability
bugzilla·2010-06-21·CVSS 5.0
CVE-2005-1080 [MEDIUM] CVE-2005-1080 jar: directory traversal vulnerability
CVE-2005-1080 jar: directory traversal vulnerability
Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2, 1.5 allows remote attackers to write arbitrary files via a .. (dot dot) in filenames in a .jar file.
Initially the directory traversal flaw was reported for fastjar (see bug #594497) but was later found to also affect jar. The vulnerability in jar was reported in January 2005 but was never corrected upstream (CVE-2005-1080). Bug #594497 has a test script to determine if the vulnerability is present in jar as well as fastjar.
Discussion:
Created java-1.6.0-openjdk tracking bugs for this issue
Affects: fedora-all [bug 601824]
---
Statement:
(none)
---
*** Bug 1180589 has been marked as a duplicate of this bug. ***
---
This issue has been
Bugzilla
CVE-2005-1080 jar: directory traversal vulnerabilities [fedora-all]
bugzilla·2010-06-08·CVSS 5.0
CVE-2005-1080 [MEDIUM] CVE-2005-1080 jar: directory traversal vulnerabilities [fedora-all]
CVE-2005-1080 jar: directory traversal vulnerabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
Forr more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=594497
Please note: this issue affects multiple suppo
Bugzilla
CVE-2010-0831 CVE-2010-2322 fastjar: directory traversal vulnerabilities
bugzilla·2010-05-20·CVSS 5.0
CVE-2010-0831 [MEDIUM] CVE-2010-0831 CVE-2010-2322 fastjar: directory traversal vulnerabilities
CVE-2010-0831 CVE-2010-2322 fastjar: directory traversal vulnerabilities
Dan Rosenberg reported a directory traversal flaw in fastjar that allows an attacker, who is able to convince a victim to extract a malicious .jar file, to overwrite arbitrary files on disk without prompting the victim. The files to be overwritten must be writable by the user extracting the .jar file.
This issue has been assigned the name CVE-2010-0831, and it is possible that it is due to an incomplete fix for CVE-2006-3619 (bug #198912).
Upon investigation, the same problem exists in the jar archiver as provided by OpenJDK and java-1.4.2-gcj-compat.
Discussion:
The jar program as provided by java-1.4.2-gcj-compat-devel in Red Hat Enterprise Linux 4 and 5 is also vulnerable to a similar issue as CVE-2006-3619, t
http://advisories.mageia.org/MGASA-2015-0158.htmlhttp://marc.info/?l=bugtraq&m=111331593310508&w=2http://marc.info/?l=oss-security&m=127602564508766&w=2http://marc.info/?l=oss-security&m=127603032617644&w=2http://rhn.redhat.com/errata/RHSA-2015-0806.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0807.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0808.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0809.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0854.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0857.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0858.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1006.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1007.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1091.htmlhttp://secunia.com/advisories/14902http://www.mandriva.com/security/advisories?name=MDVSA-2015:212http://www.securiteam.com/securitynews/5IP0C0AFGW.htmlhttp://www.securityfocus.com/bid/13083https://bugzilla.redhat.com/show_bug.cgi?id=594497https://bugzilla.redhat.com/show_bug.cgi?id=601823http://advisories.mageia.org/MGASA-2015-0158.htmlhttp://marc.info/?l=bugtraq&m=111331593310508&w=2http://marc.info/?l=oss-security&m=127602564508766&w=2http://marc.info/?l=oss-security&m=127603032617644&w=2http://rhn.redhat.com/errata/RHSA-2015-0806.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0807.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0808.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0809.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0854.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0857.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0858.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1006.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1007.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1020.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1021.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1091.htmlhttp://secunia.com/advisories/14902http://www.mandriva.com/security/advisories?name=MDVSA-2015:212http://www.securiteam.com/securitynews/5IP0C0AFGW.htmlhttp://www.securityfocus.com/bid/13083https://bugzilla.redhat.com/show_bug.cgi?id=594497https://bugzilla.redhat.com/show_bug.cgi?id=601823
2005-05-02
Published