From owner-freebsd-questions@FreeBSD.ORG Tue Sep 12 19:25:13 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 8EEE016A403 for ; Tue, 12 Sep 2006 19:25:13 +0000 (UTC) (envelope-from david.robillard@gmail.com) Received: from ug-out-1314.google.com (ug-out-1314.google.com [66.249.92.174]) by mx1.FreeBSD.org (Postfix) with ESMTP id AF9C243D6E for ; Tue, 12 Sep 2006 19:25:11 +0000 (GMT) (envelope-from david.robillard@gmail.com) Received: by ug-out-1314.google.com with SMTP id m2so1845290uge for ; Tue, 12 Sep 2006 12:25:09 -0700 (PDT) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:cc:mime-version:content-type:content-transfer-encoding:content-disposition; b=uvQisCx5k36rMVkpTet1w6kNjJRZewzSstG/59Rf7EwZ+Gl01flPbCx6CETdQZwfWYZKmbvU0sEIqQH5ErathAhJr4YUjJ/hTphijSgtSZFYU+ixfZOY+AcWoJDVPESZUMUoxLYS3ppTAAyGNdGpAw2/+WqKoTQEXz0w3TrtwNU= Received: by 10.66.222.9 with SMTP id u9mr3618971ugg; Tue, 12 Sep 2006 12:25:09 -0700 (PDT) Received: by 10.67.106.17 with HTTP; Tue, 12 Sep 2006 12:25:09 -0700 (PDT) Message-ID: <226ae0c60609121225x3a54fe80p18e85dae9c341207@mail.gmail.com> Date: Tue, 12 Sep 2006 15:25:09 -0400 From: "David Robillard" To: "FreeBSD Questions Mailing List" MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline Cc: FreeBSD Security Team Subject: jdk -- jar directory traversal vulnerability (CVE-2005-1080). X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 12 Sep 2006 19:25:13 -0000 Hi everyone, Are there any workaround or a patch for this security problem? FreeBSD Foundation's Java JDK and JRE 5.0 Update 7 binaries for FreeBSD 6.1/i386: Affected package: diablo-jdk-freebsd6.i386.1.5.0.07.00 Type of problem: jdk -- jar directory traversal vulnerability. Reference: Many thanks, David -- David Robillard UNIX systems administrator & Oracle DBA CISSP, RHCE & Sun Certified Security Administrator Montreal: +1 514 966 0122