------- Comment #16 from doko at gcc dot gnu dot org 2006-08-05 09:27 ------- Subject: Bug 28359
Author: doko Date: Sat Aug 5 09:27:11 2006 New Revision: 115945 URL: http://gcc.gnu.org/viewcvs?root=gcc&view=rev&rev=115945 Log: PR fastjar/28359 / CVE-2006-3619 2006-07-17 Richard Guenther <[EMAIL PROTECTED]> * jartool.c (extract_jar): Do not allow directory traversal to parents of the extraction root. Modified: branches/gcc-4_1-branch/fastjar/ChangeLog branches/gcc-4_1-branch/fastjar/jartool.c -- http://gcc.gnu.org/bugzilla/show_bug.cgi?id=28359