Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in a non-initial pathname component in a filename within a .jar archive, a related issue to CVE-2005-1080. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FastJar 'jartool.c'extract_jar函数目录遍历漏洞
Vulnerability Description
FastJar的jartool.c的extract_jar函数存在目录遍历漏洞,远程攻击者可利用.jar归档中某文件名未初始化的路径名组件的".."符,创建或覆盖任意文件。
CVSS Information
N/A
Vulnerability Type
N/A