ant: Incomplete fix of CVE-2018-10886

Related Vulnerabilities: CVE-2018-10886  

Debian Bug report logs - #904191
ant: Incomplete fix of CVE-2018-10886

version graph

Reported by: Salvatore Bonaccorso <carnil@debian.org>

Date: Sat, 21 Jul 2018 11:09:01 UTC

Severity: grave

Tags: security, upstream

Found in versions ant/1.9.4-3+deb8u1, ant/1.10.4-1

Fixed in versions ant/1.10.5-1, ant/1.9.4-3+deb8u2

Done: Salvatore Bonaccorso <carnil@debian.org>

Bug is archived. No further changes may be made.

Forwarded to https://bz.apache.org/bugzilla/show_bug.cgi?id=62502

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, carnil@debian.org, team@security.debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>:
Bug#904191; Package src:ant. (Sat, 21 Jul 2018 11:09:03 GMT) (full text, mbox, link).


Acknowledgement sent to Salvatore Bonaccorso <carnil@debian.org>:
New Bug report received and forwarded. Copy sent to carnil@debian.org, team@security.debian.org, Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>. (Sat, 21 Jul 2018 11:09:03 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: ant: Incomplete fix of CVE-2018-10886
Date: Sat, 21 Jul 2018 13:07:58 +0200
Source: ant
Version: 1.10.4-1
Severity: grave
Tags: security upstream
Forwarded: https://bz.apache.org/bugzilla/show_bug.cgi?id=62502
Control: fixed -1 1.10.5-1
Control: found -1 1.9.4-3+deb8u1

Hi

To CVE-2018-10886 there was a followup due to incomplete fix in
upstream 10.0.5 and 1.9.13:

 * the new allowFilesToEscapeDest didn't work when set to false and
   archive entries contained relative paths with so many ".."
   segnments that the resulting path would go beyond the file system
   root.
   Bugzilla Report 62502

Cf. https://bz.apache.org/bugzilla/show_bug.cgi?id=62502

https://github.com/apache/ant/commit/6a41d62cb9ab4e640b72cb4de42a6c211dea645d
https://github.com/apache/ant/commit/5a8c37b271677587046bfd0fea18c1675d5a6300

I requested a CVE for the incomplete fix.

Regards,
Salvatore



Marked as fixed in versions ant/1.10.5-1. Request was from Salvatore Bonaccorso <carnil@debian.org> to submit@bugs.debian.org. (Sat, 21 Jul 2018 11:09:03 GMT) (full text, mbox, link).


Marked as found in versions ant/1.9.4-3+deb8u1. Request was from Salvatore Bonaccorso <carnil@debian.org> to submit@bugs.debian.org. (Sat, 21 Jul 2018 11:09:04 GMT) (full text, mbox, link).


Marked Bug as done Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sat, 21 Jul 2018 11:12:11 GMT) (full text, mbox, link).


Notification sent to Salvatore Bonaccorso <carnil@debian.org>:
Bug acknowledged by developer. (Sat, 21 Jul 2018 11:12:11 GMT) (full text, mbox, link).


Message sent on to Salvatore Bonaccorso <carnil@debian.org>:
Bug#904191. (Sat, 21 Jul 2018 11:12:13 GMT) (full text, mbox, link).


Message #16 received at 904191-submitter@bugs.debian.org (full text, mbox, reply):

From: Salvatore Bonaccorso <carnil@debian.org>
To: control@bugs.debian.org
Cc: 904191-submitter@bugs.debian.org
Subject: closing 904191
Date: Sat, 21 Jul 2018 13:11:32 +0200
close 904191 1.10.5-1
thanks




Marked as fixed in versions ant/1.9.4-3+deb8u2. Request was from Salvatore Bonaccorso <carnil@debian.org> to control@bugs.debian.org. (Sun, 05 Aug 2018 08:21:05 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Mon, 03 Sep 2018 07:30:14 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 13:32:32 2019; Machine Name: buxtehude

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.