Debian DSA-4255-1 : ant - security update

High Nessus Plugin ID 111317

Synopsis

The remote Debian host is missing a security-related update.

Description

Danny Grander reported that the unzip and untar tasks in ant, a Java based build tool like make, allow the extraction of files outside a target directory. An attacker can take advantage of this flaw by submitting a specially crafted Zip or Tar archive to an ant build to overwrite any file writable by the user running ant.

Solution

Upgrade the ant packages.

For the stable distribution (stretch), this problem has been fixed in version 1.9.9-1+deb9u1.

See Also

https://security-tracker.debian.org/tracker/ant

https://packages.debian.org/source/stretch/ant

http://www.debian.org/security/2018/dsa-4255

Plugin Details

Severity: High

ID: 111317

File Name: debian_DSA-4255.nasl

Version: 1.1

Type: local

Agent: unix

Published: 2018/07/25

Modified: 2018/07/25

Dependencies: 12634

Risk Information

Risk Factor: High

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:ant, cpe:/o:debian:debian_linux:9.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Patch Publication Date: 2018/07/24

Reference Information

CVE: CVE-2018-10886

DSA: 4255