Debian Security Advisory
DSA-4255-1 ant -- security update
- Date Reported:
- 24 Jul 2018
- Affected Packages:
- ant
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-10886.
- More information:
-
Danny Grander reported that the unzip and untar tasks in ant, a Java based build tool like make, allow the extraction of files outside a target directory. An attacker can take advantage of this flaw by submitting a specially crafted Zip or Tar archive to an ant build to overwrite any file writable by the user running ant.
For the stable distribution (stretch), this problem has been fixed in version 1.9.9-1+deb9u1.
We recommend that you upgrade your ant packages.
For the detailed security status of ant please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ant