Directory traversal vulnerability in the Java Archive Tool (Jar) utility in J2SE SDK 1.4.2 and 1.5, and OpenJDK, allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in filenames in a .jar file.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "icedtea-6-jre-cacao",
"binary_version": "6b35-1.13.7-1ubuntu0.14.04.1"
},
{
"binary_name": "icedtea-6-jre-jamvm",
"binary_version": "6b35-1.13.7-1ubuntu0.14.04.1"
},
{
"binary_name": "openjdk-6-demo",
"binary_version": "6b35-1.13.7-1ubuntu0.14.04.1"
},
{
"binary_name": "openjdk-6-jdk",
"binary_version": "6b35-1.13.7-1ubuntu0.14.04.1"
},
{
"binary_name": "openjdk-6-jre",
"binary_version": "6b35-1.13.7-1ubuntu0.14.04.1"
},
{
"binary_name": "openjdk-6-jre-headless",
"binary_version": "6b35-1.13.7-1ubuntu0.14.04.1"
},
{
"binary_name": "openjdk-6-jre-lib",
"binary_version": "6b35-1.13.7-1ubuntu0.14.04.1"
},
{
"binary_name": "openjdk-6-jre-zero",
"binary_version": "6b35-1.13.7-1ubuntu0.14.04.1"
},
{
"binary_name": "openjdk-6-source",
"binary_version": "6b35-1.13.7-1ubuntu0.14.04.1"
}
]
}