Package        : ant
Version        : 1.9.4-3+deb8u1
CVE ID         : CVE-2018-10886


unzip and untar target tasks in ant allows the extraction of files
outside the target directory. A crafted zip or tar file submitted to
an Ant build could create or overwrite arbitrary files with the
privileges of the user running Ant.

For Debian 8 "Jessie", these problems have been fixed in version
1.9.4-3+deb8u1.

We recommend that you upgrade your ant packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1431-1: ant security update

July 19, 2018
unzip and untar target tasks in ant allows the extraction of files outside the target directory

Summary

For Debian 8 "Jessie", these problems have been fixed in version
1.9.4-3+deb8u1.

We recommend that you upgrade your ant packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Severity
Package : ant
Version : 1.9.4-3+deb8u1
CVE ID : CVE-2018-10886

Related News