SciLinux: CVE-2006-3619 SL4 gcc i386/x86_64
Summary
Date: Wed, 9 May 2007 15:12:51 -0500Reply-To: Connie SiehSender: Security Errata for Scientific Linux From: Connie Sieh Subject: Security ERRATA for SL4 gcc i386/x86_64Comments: To: scientific Synopsis: Moderate: gcc security and bug fix updateIssue date: 2007-05-01CVE Names: CVE-2006-3619Jorgen Weigert discovered a directory traversal flaw in fastjar. Anattacker could create a malicious JAR file which, if unpacked usingfastjar, could write to any files the victim had write access to.(CVE-2006-3619)SRPMS: gcc-3.4.6-8.src.rpmi386: cpp-3.4.6-8.i386.rpm gcc-3.4.6-8.i386.rpm gcc-c++-3.4.6-8.i386.rpm gcc-g77-3.4.6-8.i386.rpm gcc-gnat-3.4.6-8.i386.rpm gcc-java-3.4.6-8.i386.rpm gcc-objc-3.4.6-8.i386.rpm libf2c-3.4.6-8.i386.rpm libgcc-3.4.6-8.i386.rpm libgcj-3.4.6-8.i386.rpm libgcj-devel-3.4.6-8.i386.rpm libgnat-3.4.6-8.i386.rpm libobjc-3.4.6-8.i386.rpm libstdc++-3.4.6-8.i386.rpm libstdc++-devel-3.4.6-8.i386.rpmx86_64: cpp-3.4.6-8.x86_64.rpm gcc-3.4.6-8.x86_64.rpm gcc-c++-3.4.6-8.x86_64.rpm gcc-g77-3.4.6-8.x86_64.rpm gcc-gnat-3.4.6-8.x86_64.rpm gcc-java-3.4.6-8.x86_64.rpm gcc-objc-3.4.6-8.x86_64.rpm libf2c-3.4.6-8.i386.rpm libf2c-3.4.6-8.x86_64.rpm libgcc-3.4.6-8.i386.rpm libgcc-3.4.6-8.x86_64.rpm libgcj-3.4.6-8.i386.rpm libgcj-3.4.6-8.x86_64.rpm libgcj-devel-3.4.6-8.x86_64.rpm libgnat-3.4.6-8.i386.rpm libgnat-3.4.6-8.x86_64.rpm libobjc-3.4.6-8.i386.rpm libobjc-3.4.6-8.x86_64.rpm libstdc++-3.4.6-8.i386.rpm libstdc++-3.4.6-8.x86_64.rpm libstdc++-devel-3.4.6-8.i386.rpm libstdc++-devel-3.4.6-8.x86_64.rpm-Connie Sieh-Troy Dawson