Bug 846174 (CVE-2013-2186) - VUL-0: CVE-2013-2186: jakarta-commons-fileupload: null byte injection flaw
Summary: VUL-0: CVE-2013-2186: jakarta-commons-fileupload: null byte injection flaw
Status: RESOLVED FIXED
Alias: CVE-2013-2186
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P2 - High : Major
Target Milestone: ---
Deadline: 2013-10-23
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp1:54733
Keywords:
Depends on:
Blocks:
 
Reported: 2013-10-16 09:52 UTC by Victor Pereira
Modified: 2013-11-25 13:58 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Victor Pereira 2013-10-16 09:52:56 UTC
CVE-2013-2186

A poison null byte flaw was found in the implementation of the DiskFileItem class. A remote attacker could able to supply a serialized instance of the DiskFileItem class, which would be deserialized on a server, could use this flaw to write arbitrary content to any location on the server that is permitted by the user running the application server process.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2186
https://bugzilla.redhat.com/show_bug.cgi?id=974814
http://svn.apache.org/viewvc/commons/proper/fileupload/trunk/src/main/java/org/apache/commons/fileupload/disk/DiskFileItem.java?r1=1460343&r2=1507048 (patch on the mainline)
Comment 1 Swamp Workflow Management 2013-10-16 10:02:37 UTC
The SWAMPID for this issue is 54731.
This issue was rated as important.
Please submit fixed packages until 2013-10-23.
When done, please reassign the bug to security-team@suse.de.
Patchinfo will be handled by security team.
Comment 4 Michal Vyskocil 2013-10-17 09:02:18 UTC
set to openSUSE as 203572
Comment 5 Bernhard Wiedemann 2013-10-17 10:02:02 UTC
This is an autogenerated message for OBS integration:
This bug (846174) was mentioned in
https://build.opensuse.org/request/show/203572 13.1+12.2+12.3 / jakarta-commons-fileupload
Comment 6 Bernhard Wiedemann 2013-10-18 12:00:14 UTC
This is an autogenerated message for OBS integration:
This bug (846174) was mentioned in
https://build.opensuse.org/request/show/203726 Factory / jakarta-commons-fileupload
Comment 7 Swamp Workflow Management 2013-10-23 09:04:20 UTC
openSUSE-SU-2013:1571-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 846174
CVE References: CVE-2013-2186
Sources used:
openSUSE 12.3 (src):    jakarta-commons-fileupload-1.1.1-114.4.1
openSUSE 12.2 (src):    jakarta-commons-fileupload-1.1.1-112.4.1
Comment 8 Bernhard Wiedemann 2013-10-24 10:00:15 UTC
This is an autogenerated message for OBS integration:
This bug (846174) was mentioned in
https://build.opensuse.org/request/show/204494 Factory / jakarta-commons-fileupload
Comment 9 Bernhard Wiedemann 2013-10-27 02:00:19 UTC
This is an autogenerated message for OBS integration:
This bug (846174) was mentioned in
https://build.opensuse.org/request/show/204877 Evergreen:11.2:Test / jakarta-commons-fileupload
Comment 10 Swamp Workflow Management 2013-10-28 21:04:19 UTC
openSUSE-SU-2013:1596-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 846174
CVE References: CVE-2013-2186
Sources used:
openSUSE 11.4 (src):    jakarta-commons-fileupload-1.1.1-109.2
Comment 11 Bernhard Wiedemann 2013-11-01 01:00:25 UTC
This is an autogenerated message for OBS integration:
This bug (846174) was mentioned in
https://build.opensuse.org/request/show/205485 Evergreen:11.2 / jakarta-commons-fileupload
Comment 12 Swamp Workflow Management 2013-11-12 14:51:07 UTC
Update released for: jakarta-commons-fileupload, jakarta-commons-fileupload-javadoc
Products:
SLE-SERVER 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP3 (i386, x86_64)
Comment 13 Swamp Workflow Management 2013-11-12 14:55:56 UTC
Update released for: jakarta-commons-fileupload, jakarta-commons-fileupload-javadoc
Products:
SLE-SERVER 11-SP2 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP2 (i386, x86_64)
Comment 14 Swamp Workflow Management 2013-11-12 15:04:17 UTC
Update released for: jakarta-commons-fileupload, jakarta-commons-fileupload-javadoc
Products:
SLE-SERVER 11-SP1-TERADATA (x86_64)
SUSE-MANAGER 1.2 (x86_64)
Comment 15 Marcus Meissner 2013-11-25 13:58:40 UTC
released