From owner-freebsd-questions@FreeBSD.ORG Tue Sep 12 20:52:35 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id A4C1516A412; Tue, 12 Sep 2006 20:52:35 +0000 (UTC) (envelope-from remko@freebsd.org) Received: from caelis.elvandar.org (caelis.elvandar.org [217.148.169.59]) by mx1.FreeBSD.org (Postfix) with ESMTP id D24B643D7C; Tue, 12 Sep 2006 20:52:33 +0000 (GMT) (envelope-from remko@freebsd.org) Received: from localhost (caelis.elvandar.org [217.148.169.59]) by caelis.elvandar.org (Postfix) with ESMTP id 18CCB92FDE2; Tue, 12 Sep 2006 22:52:33 +0200 (CEST) Received: from caelis.elvandar.org ([217.148.169.59]) by localhost (caelis.elvandar.org [217.148.169.59]) (amavisd-new, port 10024) with ESMTP id 27039-03; Tue, 12 Sep 2006 22:52:32 +0200 (CEST) Message-ID: <45071E18.5020908@FreeBSD.org> Date: Tue, 12 Sep 2006 22:52:40 +0200 From: Remko Lodder User-Agent: Thunderbird 1.5.0.5 (Macintosh/20060719) MIME-Version: 1.0 To: David Robillard References: <226ae0c60609121225x3a54fe80p18e85dae9c341207@mail.gmail.com> In-Reply-To: <226ae0c60609121225x3a54fe80p18e85dae9c341207@mail.gmail.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Scanned: by the elvandar.org maildomain Cc: FreeBSD Security Team , FreeBSD Questions Mailing List Subject: Re: jdk -- jar directory traversal vulnerability (CVE-2005-1080). X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: remko@FreeBSD.org List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 12 Sep 2006 20:52:35 -0000 David Robillard wrote: > Hi everyone, > > Are there any workaround or a patch for this security problem? > > FreeBSD Foundation's Java JDK and JRE 5.0 Update 7 binaries for > FreeBSD 6.1/i386: > > Affected package: diablo-jdk-freebsd6.i386.1.5.0.07.00 > Type of problem: jdk -- jar directory traversal vulnerability. > Reference: > > > > Many thanks, > > David Hello david, I corrected the entry, it should be fixed within little notice :) Thanks for the report! -- Kind regards, Remko Lodder ** remko@elvandar.org FreeBSD ** remko@FreeBSD.org /* Quis custodiet ipsos custodes */