Debian DSA-4255-1 : ant - security update

high Nessus Plugin ID 111317

Synopsis

The remote Debian host is missing a security-related update.

Description

Danny Grander reported that the unzip and untar tasks in ant, a Java based build tool like make, allow the extraction of files outside a target directory. An attacker can take advantage of this flaw by submitting a specially crafted Zip or Tar archive to an ant build to overwrite any file writable by the user running ant.

Solution

Upgrade the ant packages.

For the stable distribution (stretch), this problem has been fixed in version 1.9.9-1+deb9u1.

See Also

https://security-tracker.debian.org/tracker/source-package/ant

https://packages.debian.org/source/stretch/ant

https://www.debian.org/security/2018/dsa-4255

Plugin Details

Severity: High

ID: 111317

File Name: debian_DSA-4255.nasl

Version: 1.3

Type: local

Agent: unix

Published: 7/25/2018

Updated: 11/13/2018

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:ant, cpe:/o:debian:debian_linux:9.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 7/24/2018

Reference Information

CVE: CVE-2018-10886

DSA: 4255