Lucene search

K
cve[email protected]CVE-2010-2322
HistoryJun 18, 2010 - 6:30 p.m.

CVE-2010-2322

2010-06-1818:30:01
CWE-22
web.nvd.nist.gov
113
cve-2010-2322
absolute path traversal
fastjar 0.98
remote attackers
jar archive
file overwrite

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

6.7 Medium

AI Score

Confidence

Low

0.013 Low

EPSS

Percentile

86.1%

Absolute path traversal vulnerability in the extract_jar function in jartool.c in FastJar 0.98 allows remote attackers to create or overwrite arbitrary files via a full pathname for a file within a .jar archive, a related issue to CVE-2010-0831. NOTE: this vulnerability exists because of an incomplete fix for CVE-2006-3619.

Affected configurations

NVD
Node
matthias_klosefastjarMatch0.98

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

6.7 Medium

AI Score

Confidence

Low

0.013 Low

EPSS

Percentile

86.1%