From owner-freebsd-questions@FreeBSD.ORG Tue Sep 12 22:04:53 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 81DE516A5AB; Tue, 12 Sep 2006 22:04:53 +0000 (UTC) (envelope-from nectar@FreeBSD.org) Received: from mail.phi23.org (phi23.org [161.58.133.165]) by mx1.FreeBSD.org (Postfix) with ESMTP id 3336543D45; Tue, 12 Sep 2006 22:04:53 +0000 (GMT) (envelope-from nectar@FreeBSD.org) Received: from [17.202.43.159] (A17-202-43-159.apple.com [17.202.43.159]) (using TLSv1 with cipher RC4-SHA (128/128 bits)) (Client did not present a certificate) by mail.phi23.org (Postfix) with ESMTP id 5D4CB28FE2; Tue, 12 Sep 2006 22:04:52 +0000 (UTC) In-Reply-To: <45071E18.5020908@FreeBSD.org> References: <226ae0c60609121225x3a54fe80p18e85dae9c341207@mail.gmail.com> <45071E18.5020908@FreeBSD.org> Mime-Version: 1.0 (Apple Message framework v752.2) Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed Message-Id: <684DAC90-B7E7-4EEA-A42B-83E95D4AF830@FreeBSD.org> Content-Transfer-Encoding: 7bit From: Jacques Vidrine Date: Tue, 12 Sep 2006 15:04:51 -0700 To: remko@FreeBSD.org X-Mailer: Apple Mail (2.752.2) Cc: FreeBSD Security Team , David Robillard , FreeBSD Questions Mailing List Subject: Re: jdk -- jar directory traversal vulnerability (CVE-2005-1080). X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 12 Sep 2006 22:04:53 -0000 On 2006-09-12, at 13:52:40, Remko Lodder wrote: > David Robillard wrote: >> Hi everyone, >> Are there any workaround or a patch for this security problem? >> FreeBSD Foundation's Java JDK and JRE 5.0 Update 7 binaries for >> FreeBSD 6.1/i386: >> Affected package: diablo-jdk-freebsd6.i386.1.5.0.07.00 >> Type of problem: jdk -- jar directory traversal vulnerability. >> Reference: > ae7c-11d9-837d-000e0c2e438a.html> Many thanks, >> David > > Hello david, > > I corrected the entry, it should be fixed within little notice :) Hey, hold on a second... are you sure this has been fixed? As far as I know, Sun has never issues a patch for this vulnerability. Yay Sun! Cheers, -- Jacques Vidrine