Ubuntu Security Notice 953-1 - Dan Rosenberg discovered that fastjar incorrectly handled file paths containing ".." when unpacking archives. If a user or an automated system were tricked into unpacking a specially crafted jar file, arbitrary files could be overwritten with user privileges.
d12c3ea85ae44c20eb207fcdf83743df