CVE-2010-0831

Description

Directory traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a non-initial pathname component in a filename within a .jar archive, a related issue to CVE-2005-1080. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
1.855

Associated Vulnerability

VulnerabilityOS Platform
(RHSA-2011:0025) Low: gcc security and bug fix update cpp-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update cpp-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-c++-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-c++-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-gfortran-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-gfortran-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-gnat-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-gnat-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-java-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-java-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-objc-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-objc-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-objc++-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update gcc-objc++-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libgcc-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libgcc-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libgcj-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libgcj-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libgcj-devel-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libgcj-devel-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libgcj-src-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libgcj-src-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libgfortran-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libgfortran-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libgnat-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libgnat-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libmudflap-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libmudflap-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libmudflap-devel-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libmudflap-devel-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libobjc-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libobjc-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libstdc++-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libstdc++-4.1.2-50.el5.x86_64.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libstdc++-devel-4.1.2-50.el5.i386.rpmLinux
(RHSA-2011:0025) Low: gcc security and bug fix update libstdc++-devel-4.1.2-50.el5.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234