Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 141562 - sys-devel/gcc fastjar directory traversal problem (CVE-2006-3619)
Summary: sys-devel/gcc fastjar directory traversal problem (CVE-2006-3619)
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://gcc.gnu.org/PR28359
Whiteboard: B4 [noglsa] DerCorny
Keywords:
Depends on:
Blocks:
 
Reported: 2006-07-24 03:13 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2007-03-09 22:05 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
patch to fix directory traversal (fastjar.patch,1.26 KB, patch)
2006-07-24 08:48 UTC, Stefan Cornelius (RETIRED)
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-07-24 03:13:48 UTC
fastjar contains the following security problem:

When a JAR archive is extracted with filenames with "../" inside, it can
extract files outside of the current directory (a so called directory
traversal).

Unconspicious users unpacking such files could overwrite their own files,
or even system files when being root.

I am attaching a sample "cups.jar" from an earlier CUPS tarball, which exposes
this problem.
Comment 1 Stefan Cornelius (RETIRED) gentoo-dev 2006-07-24 08:48:07 UTC
Created attachment 92619 [details, diff]
patch to fix directory traversal

patch grabbed from here
http://gcc.gnu.org/bugzilla/attachment.cgi?id=11904
Comment 2 Stefan Cornelius (RETIRED) gentoo-dev 2006-07-24 08:55:00 UTC
please provide a fixed ebuild, thanks
Comment 3 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-09-05 06:14:14 UTC
toolchain, any news on this one?
Comment 4 SpanKY gentoo-dev 2006-09-10 22:29:10 UTC
this will be included in gcc-4.1.1-r2 and higher

should we bother with a GLSA ?
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-09-11 00:40:13 UTC
According to policy we should vote an GLSA release. Personally I would vote NO.
Comment 6 Wolf Giesen (RETIRED) gentoo-dev 2006-09-11 02:57:47 UTC
Hm. I tend to vote no, too (although I usually take directory traversals seriously, especially since Gentoo's a prime target in this very case ^^).
Comment 7 SpanKY gentoo-dev 2006-09-11 09:25:58 UTC
yes, but i thought in general we are not going to do GLSAs for toolchain
Comment 8 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-09-13 23:15:54 UTC
SpanKY any news on this one?

I'm still awaiting answer to my mail to security@ before I can upgrade policy wrt toolchain. I'll just resend it now.
Comment 9 SpanKY gentoo-dev 2006-09-13 23:20:27 UTC
what are you talking about ?  i gave you your news in comment #4
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-09-26 09:25:41 UTC
SpanKY is gcc-4.1.1-r2 ready for stable marking?
Comment 11 SpanKY gentoo-dev 2006-09-26 13:20:42 UTC
i was going to put it into ~arch in the next week

but i still dont see much point in pushing this into stable as it's part of our toolchain
Comment 12 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2006-09-26 14:03:06 UTC
SpanKY I've been asking on -security for clarification on the toolchain issue. Could you please answer to that mail and we can get this bug closed?
Comment 13 SpanKY gentoo-dev 2006-09-26 20:27:10 UTC
i responded when you first sent out the e-mail
Comment 14 Raphael Marichez (Falco) (RETIRED) gentoo-dev 2007-03-09 22:05:05 UTC
gcc-4.1.1-r3 is stable and this bug is obsolete, feel free to reopen if you disagree