It was reported [1] that jar(1) is susceptible to a directory traversal vulnerability. While extracting an archive, it will happily use absolute and relative paths taken from the archive. This can be exploited by a malicious archive to write files outside the current directory. This issue might be relevant to the (incomplete) fix of CVE-2005-1080. Please note that CVE-2005-1080 talks about .. only. [1]: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774953
Created java-1.7.0-openjdk tracking bugs for this issue: Affects: fedora-all [bug 1180591]
Created java-1.8.0-openjdk tracking bugs for this issue: Affects: fedora-all [bug 1180593]
Marking this as duplicate of CVE-2005-1080. *** This bug has been marked as a duplicate of bug 606442 ***