cvs commit: ports/java/jdk14 Makefile ports/java/jdk14/files
patch-j2se-jar-Main.java patch-j2se-resources-jar.properties
Greg Lewis
glewis at FreeBSD.org
Wed May 11 14:18:40 PDT 2005
glewis 2005-05-11 21:18:40 UTC
FreeBSD ports repository
Modified files:
java/jdk14 Makefile
Added files:
java/jdk14/files patch-j2se-jar-Main.java
patch-j2se-resources-jar.properties
Log:
. Ensure that when files are extracted that their fully resolved path lies
in or below the current working directory. Fixes a security problem with
jar(1).
This fix may change to be compatible with whatever fix Sun applies when
they release a fixed version of 1.5.
. Bump PORTREVISION for this fix.
Approved by: maintainer timeout
Security: http://vuxml.FreeBSD.org/18e5428f-ae7c-11d9-837d-000e0c2e438a.html
Revision Changes Path
1.90 +1 -0 ports/java/jdk14/Makefile
1.1 +58 -0 ports/java/jdk14/files/patch-j2se-jar-Main.java (new)
1.1 +13 -0 ports/java/jdk14/files/patch-j2se-resources-jar.properties (new)
More information about the cvs-all
mailing list