{"id":"openSUSE-SU-2026:21891-1","summary":"Security update for ant","details":"This update for ant fixes the following issues:\n\n- CVE-2021-36374: excessive memory allocation when reading a specially crafted ZIP archive or a derived formats\n  (bsc#1188469).\n- CVE-2025-7962: jakarta: improper neutralization of \\r and \\n UTF-8 characters can lead to SMTP injection\n  (bsc#1246873).\n- CVE-2026-78254: path traversal in ftp and scp tasks allows for arbitrary file writes (bsc#1280015).\n\nChanges for ant:\n\n- Upgrade to version 1.10.18\n * Breaking changes:\n + the default value for \u003cftp\u003e's useSecureDataChannel has been\n changed to true which means using ftps now also tries to use\n an encrypted data channel by default.\n + the \u003cftp\u003e and \u003cscp\u003e tasks have new allowFilesToEscapeDest\n attributes. When set to false - which is the default - the\n tasks will not download files or create directories outside\n the designated destination directory when downloading from the\n remote server. In the unlikely case you need the old bahaviour\n of writing outside the destination directory you must set the\n value to true explicitly.\n * Other changes:\n + when using the SOURCE_DATE_EPOCH environment variable to set\n the time for \u003ctstamp\u003e the timezone will now be set to UTC for\n DSTAMP, TSTAMP and TODAY. This also applies to nested formats\n where the locale now also defaults to en_US unless it (or the\n timezone) have been set explicitly.\n + Upgraded the jakarta.mail dependency to 2.0.2 because of\n bsc#1246873, CVE-2025-7962.\n + the SOURCE_DATE_EPOCH environment variable as well as the\n magic ant.tstamp.now and ant.tstamp.now.iso properties now\n also affect the timestamp added to a properties file written\n by \u003cpropertyfile\u003e - but only if jdkproperties has its default\n value of false.\n + a new method getBuildDate in Project can now be used to\n calculate a notion of a \"build date\" that consults the\n SOURCE_DATE_EPOCH environment variable as well as the magic\n ant.tstamp.now and ant.tstamp.now.iso properties in this order\n which you can use if you want to obtain a reproducible\n timestamp in tasks you write yourself.\n + The \"record\" task now has a new \"relativeToBaseDir\" attribute,\n which can be set to \"yes\" or \"no\", to control where the\n recorder's file gets created. In the absence of this\n attribute, if the \"name\" of the recorder was a relative path,\n then the recorder would create the file in the current working\n directory of the process. With this new attribute, the\n recorder can be configured to create that file in the basedir\n of the project.\n * Fixed bugs:\n + When running with \"microsoft\" Java, Ant used to hardcode the\n \"$JAVA_HOME/Packages\" directory in the runtime Paths for\n certain tasks. The JDK shipped by Microsoft no longer contains\n that directory (for several decades now). As a result, when\n running with \"microsoft\" Java, an exception would be raised\n due to the missing directory. This has now been fixed and Ant\n no longer adds that directory to the Java runtime Paths.\n + Inaccuracies in the documentation of the \"record\" task have\n been fixed.\n + \u003cmappedresources\u003e with \"enableMultipleMappings\" set to \"true\"\n threw a NullPointerException if the mapper didn't apply to\n one of the resources. Unmapped resources are now omitted from\n the collection.\n- Changes of version 1.10.17\n + The JavaEnvUtils and FileUtils classes statically depend on\n each other since Ant 1.10.16 making it impossible to load\n JavaEnvUtils without loading FileUtils first causing\n NullPointerException for programmatic use on Windows. This\n affected Eclipse and may also affect other projects using Ant\n as a library. The classes can now be loaded independently\n again.\n- Changes of version 1.10.16\n + \u003cxslt\u003e now uses the same logic to compare file timestamps when\n determining whether a target file is out-of-date with respect\n to the source file or stylesheet that most other tasks use.\n This means it will assume a default timestamp granularity that\n depends on the current operating system.\n A new granularity attribute allows you to override the assumed\n granularity.\n Under certain edge cases this means xslt will now not process\n files it would have processed before (when the timestamps of\n source or stylesheet are very close or even equal to the\n timestamp of the target). In this case you can set granularity\n to 0 to get back to the behavior of 1.10.15.\n + the \u003cmail\u003e task as well as MailLogger will now check the server\n identity as specified by RFC 2595 when JavaMail is used in\n combination with TLS (plain TLS or StartTLS).\n The check can be disabled with a new MailLogger property\n MailLogger.tls.checkserveridentity or a new \u003cmail\u003e task\n attribute checkServerIdentity.\n + Ant now recognizes Windows junctions and treats them just like\n symbolic links in general. With this builds on Windows that\n use followSymlinks=\"false\" and rely on Ant following Windows\n junctions will break. In order to get the old behavior you\n need to set followSymlinks to true and exclude real symbolic\n links via the \u003csymlink\u003e selector.\n + \u003cscp\u003e now properly handles IPv6 addresses as hostnames.\n + javac task has been fixed to generate the \"-classpath\" option\n only when there are any classpath elements present.\n + URLResource#getName could strip the first character of a\n resource path even if it was not a file separator.\n + ant.bat now exits with a non-zero exit code if ANT_HOME is not\n set.\n + A regression in ftp task caused some files to not be\n downloaded. That has been fixed now.\n + Ant will no longer set a java.lang.SecurityManager at runtime\n if the \"java.security.manager\" system property is set to\n \"disallow\".\n + \u003cmail\u003e and MailLogger can now enforce the use of STARTLS\n rather than silently fall back to unencrypted authentication\n via a new MailLogger property and a new \u003cmail\u003e task attribute.\n + added a Windows specific \u003cmklink\u003e task that can be used to\n create hard links, symbolic links and junctions.\n + added \u003cdelete link=\"...\"\u003e that can be used delete symbolic\n links or Windows junctions. For symbolic links this duplicates\n what \u003csymlink action=\"delete\" ...\u003e does - it has been\n introduced to handle symlinks and junctions via a single API.\n + added \u003ccanCreateSymlink\u003e condition that evaluates to true if\n the current Ant process can create symbolic links.\n + added \u003cwindowsjunction\u003e file selector which only selects\n directories that are Windows junctions.\n + added a new actOnLinkTargets attribute to \u003csetpermissions\u003e to\n control whether the permissions apply to a symbolic link or\n Windows junction or the target of the respective links. The\n old behavior of changing the link's target remains as default.\n + a new combination of attributes allows \u003csshexec\u003e to mask\n sensitive data specified for the command line to execute.\n + just omit completely the Created-By if SOURCE_DATE_EPOCH is\n set\n - \u003cget\u003e has a new attribute authenticateOnRedirect that can be\n used to prevent Ant from sending the configured credentials\n builds that rely on credentials being used on the redirected\n - the PropertyEnumerator change introduced in 1.10.9 proved to\n be not fully backwards compatible when combined with certain\n - \u003cscp\u003e may leak connections when trying to preserve the last\n modified timestamps of files transferred recursively from a\n environment variable value to an incorrect date. This has now\n - fetch.xml didn't set up non-default repositories propery and\n build script would change permissions on unrelated files in\n the destination directory. This is now fixed and such\n unrelated files in the destination directory will be left\n - parsing tar entries with multiple NUL bytes in their name\n - loadresource might log warnings even though quiet was set to\n repackaged Jakarta Mail package rather than javax Mail.\n - org.apache.tools.ant.BuildLogger now has a new method\n getMessageOutputLevel() which returns the currently set\n CVE-2021-36374, bsc#1188469\n Excessive memory allocation when reading a specially\n * Prevent potential deadlocks in org.apache.tools.ant.IntrospectionHelper.\n * The implementation of AntClassLoader#findResources() has been changed to optimize\n- Update to ant 1.8.2\n","modified":"2026-09-25T18:23:49.549484243Z","published":"2026-09-20T14:11:16Z","related":["CVE-2021-36374","CVE-2025-7962","CVE-2026-78254"],"upstream":["CVE-2021-36374","CVE-2025-7962","CVE-2026-78254"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188469"},{"type":"REPORT","url":"https://bugzilla.suse.com/1246873"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280015"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-36374"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-7962"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-78254"}],"affected":[{"package":{"name":"ant","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/ant&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.18-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"ant-jdepend":"1.10.18-160000.1.1","ant-jakartamail":"1.10.18-160000.1.1","ant":"1.10.18-160000.1.1","ant-jmf":"1.10.18-160000.1.1","ant-testutil":"1.10.18-160000.1.1","ant-apache-bsf":"1.10.18-160000.1.1","ant-apache-bcel":"1.10.18-160000.1.1","ant-commons-logging":"1.10.18-160000.1.1","ant-junit":"1.10.18-160000.1.1","ant-imageio":"1.10.18-160000.1.1","ant-commons-net":"1.10.18-160000.1.1","ant-apache-log4j":"1.10.18-160000.1.1","ant-apache-xalan2":"1.10.18-160000.1.1","ant-apache-resolver":"1.10.18-160000.1.1","ant-javamail":"1.10.18-160000.1.1","ant-xz":"1.10.18-160000.1.1","ant-jsch":"1.10.18-160000.1.1","ant-swing":"1.10.18-160000.1.1","ant-antlr":"1.10.18-160000.1.1","ant-manual":"1.10.18-160000.1.1","ant-apache-regexp":"1.10.18-160000.1.1","ant-apache-oro":"1.10.18-160000.1.1","ant-scripts":"1.10.18-160000.1.1","ant-junit5":"1.10.18-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21891-1.json"}},{"package":{"name":"ant-antlr","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/ant-antlr&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.18-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"ant-manual":"1.10.18-160000.1.1","ant-apache-resolver":"1.10.18-160000.1.1","ant-apache-xalan2":"1.10.18-160000.1.1","ant-apache-oro":"1.10.18-160000.1.1","ant-jsch":"1.10.18-160000.1.1","ant-javamail":"1.10.18-160000.1.1","ant-commons-net":"1.10.18-160000.1.1","ant-testutil":"1.10.18-160000.1.1","ant-antlr":"1.10.18-160000.1.1","ant-jakartamail":"1.10.18-160000.1.1","ant-commons-logging":"1.10.18-160000.1.1","ant-swing":"1.10.18-160000.1.1","ant-xz":"1.10.18-160000.1.1","ant-scripts":"1.10.18-160000.1.1","ant-apache-regexp":"1.10.18-160000.1.1","ant-imageio":"1.10.18-160000.1.1","ant-apache-bsf":"1.10.18-160000.1.1","ant-jdepend":"1.10.18-160000.1.1","ant-junit5":"1.10.18-160000.1.1","ant-jmf":"1.10.18-160000.1.1","ant-junit":"1.10.18-160000.1.1","ant":"1.10.18-160000.1.1","ant-apache-log4j":"1.10.18-160000.1.1","ant-apache-bcel":"1.10.18-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21891-1.json"}},{"package":{"name":"ant-junit","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/ant-junit&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.18-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"ant-javamail":"1.10.18-160000.1.1","ant":"1.10.18-160000.1.1","ant-imageio":"1.10.18-160000.1.1","ant-jdepend":"1.10.18-160000.1.1","ant-jsch":"1.10.18-160000.1.1","ant-antlr":"1.10.18-160000.1.1","ant-apache-bcel":"1.10.18-160000.1.1","ant-apache-regexp":"1.10.18-160000.1.1","ant-junit":"1.10.18-160000.1.1","ant-commons-net":"1.10.18-160000.1.1","ant-apache-log4j":"1.10.18-160000.1.1","ant-apache-resolver":"1.10.18-160000.1.1","ant-testutil":"1.10.18-160000.1.1","ant-commons-logging":"1.10.18-160000.1.1","ant-jmf":"1.10.18-160000.1.1","ant-junit5":"1.10.18-160000.1.1","ant-swing":"1.10.18-160000.1.1","ant-manual":"1.10.18-160000.1.1","ant-scripts":"1.10.18-160000.1.1","ant-xz":"1.10.18-160000.1.1","ant-apache-xalan2":"1.10.18-160000.1.1","ant-apache-oro":"1.10.18-160000.1.1","ant-jakartamail":"1.10.18-160000.1.1","ant-apache-bsf":"1.10.18-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21891-1.json"}},{"package":{"name":"ant-junit5","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/ant-junit5&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10.18-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"ant-apache-oro":"1.10.18-160000.1.1","ant-apache-log4j":"1.10.18-160000.1.1","ant-apache-bcel":"1.10.18-160000.1.1","ant-commons-net":"1.10.18-160000.1.1","ant-swing":"1.10.18-160000.1.1","ant-imageio":"1.10.18-160000.1.1","ant-xz":"1.10.18-160000.1.1","ant-scripts":"1.10.18-160000.1.1","ant-javamail":"1.10.18-160000.1.1","ant-jakartamail":"1.10.18-160000.1.1","ant-antlr":"1.10.18-160000.1.1","ant-jmf":"1.10.18-160000.1.1","ant-junit5":"1.10.18-160000.1.1","ant-apache-bsf":"1.10.18-160000.1.1","ant-testutil":"1.10.18-160000.1.1","ant-commons-logging":"1.10.18-160000.1.1","ant-manual":"1.10.18-160000.1.1","ant-apache-xalan2":"1.10.18-160000.1.1","ant":"1.10.18-160000.1.1","ant-jdepend":"1.10.18-160000.1.1","ant-junit":"1.10.18-160000.1.1","ant-apache-regexp":"1.10.18-160000.1.1","ant-jsch":"1.10.18-160000.1.1","ant-apache-resolver":"1.10.18-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21891-1.json"}}],"schema_version":"1.9.0"}