_______________________________________________________________________
Package : jetty5
Date : October 29, 2009
Affected: 2009.0, 2009.1
_______________________________________________________________________
Problem Description:
A vulnerability has been identified and corrected in jetty5:
Directory traversal vulnerability in the HTTP server in Mort Bay
Jetty before 6.1.17, and 7.0.0.M2 and earlier 7.x versions, allows
remote attackers to access arbitrary files via directory traversal
sequences in the URI (CVE-2009-1523).
This update fixes this vulnerability.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-1523
_______________________________________________________________________