Debian Security Update DSA-4255 ant - security update

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,813
Reaction score
74
Credits
-1,257
Danny Grander reported that the unzip and untar tasks in ant, a Java based build tool like make, allow the extraction of files outside a target directory. An attacker can take advantage of this flaw by submitting a specially crafted Zip or Tar archive to an ant build to overwrite any file writable by the user running ant.

Continue reading...
 


Follow Linux.org

Members online

No members online now.

Top