ZipFile bypasses file delete permission check

XMLWordPrintable

    • Type: Bug
    • Resolution: Fixed
    • Priority: P1
    • 1.4.0
    • Affects Version/s: 1.3.0
    • Component/s: core-libs
    • None
    • beta
    • generic
    • solaris_7
    • Verified

      The java.util.zip.ZipFile constructor can be used to open a file with
      a "delete" mode set. But the only SecurityManager call that is done
      is checkRead. A file that cannot be deleted by File.delete() can
      bypass security and be deleted using ZipFile.

      dean.long@Eng 2000-07-05

            Assignee:
            Btplusnull User (Inactive)
            Reporter:
            Dean Long
            Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

              Created:
              Updated:
              Resolved:
              Imported:
              Indexed: