cvs commit: ports/java/jdk14 Makefile ports/java/jdk14/files patch-j2se-jar-Main.java patch-j2se-resources-jar.properties

Greg Lewis glewis at FreeBSD.org
Wed May 11 14:18:40 PDT 2005


glewis      2005-05-11 21:18:40 UTC

  FreeBSD ports repository

  Modified files:
    java/jdk14           Makefile 
  Added files:
    java/jdk14/files     patch-j2se-jar-Main.java 
                         patch-j2se-resources-jar.properties 
  Log:
  . Ensure that when files are extracted that their fully resolved path lies
    in or below the current working directory.  Fixes a security problem with
    jar(1).
  
    This fix may change to be compatible with whatever fix Sun applies when
    they release a fixed version of 1.5.
  . Bump PORTREVISION for this fix.
  
  Approved by:    maintainer timeout
  Security: http://vuxml.FreeBSD.org/18e5428f-ae7c-11d9-837d-000e0c2e438a.html
  
  Revision  Changes    Path
  1.90      +1 -0      ports/java/jdk14/Makefile
  1.1       +58 -0     ports/java/jdk14/files/patch-j2se-jar-Main.java (new)
  1.1       +13 -0     ports/java/jdk14/files/patch-j2se-resources-jar.properties (new)


More information about the cvs-all mailing list