Bugzilla – Bug 846174
VUL-0: CVE-2013-2186: jakarta-commons-fileupload: null byte injection flaw
Last modified: 2013-11-25 13:58:40 UTC
CVE-2013-2186 A poison null byte flaw was found in the implementation of the DiskFileItem class. A remote attacker could able to supply a serialized instance of the DiskFileItem class, which would be deserialized on a server, could use this flaw to write arbitrary content to any location on the server that is permitted by the user running the application server process. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-2186 https://bugzilla.redhat.com/show_bug.cgi?id=974814 http://svn.apache.org/viewvc/commons/proper/fileupload/trunk/src/main/java/org/apache/commons/fileupload/disk/DiskFileItem.java?r1=1460343&r2=1507048 (patch on the mainline)
The SWAMPID for this issue is 54731. This issue was rated as important. Please submit fixed packages until 2013-10-23. When done, please reassign the bug to security-team@suse.de. Patchinfo will be handled by security team.
set to openSUSE as 203572
This is an autogenerated message for OBS integration: This bug (846174) was mentioned in https://build.opensuse.org/request/show/203572 13.1+12.2+12.3 / jakarta-commons-fileupload
This is an autogenerated message for OBS integration: This bug (846174) was mentioned in https://build.opensuse.org/request/show/203726 Factory / jakarta-commons-fileupload
openSUSE-SU-2013:1571-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 846174 CVE References: CVE-2013-2186 Sources used: openSUSE 12.3 (src): jakarta-commons-fileupload-1.1.1-114.4.1 openSUSE 12.2 (src): jakarta-commons-fileupload-1.1.1-112.4.1
This is an autogenerated message for OBS integration: This bug (846174) was mentioned in https://build.opensuse.org/request/show/204494 Factory / jakarta-commons-fileupload
This is an autogenerated message for OBS integration: This bug (846174) was mentioned in https://build.opensuse.org/request/show/204877 Evergreen:11.2:Test / jakarta-commons-fileupload
openSUSE-SU-2013:1596-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 846174 CVE References: CVE-2013-2186 Sources used: openSUSE 11.4 (src): jakarta-commons-fileupload-1.1.1-109.2
This is an autogenerated message for OBS integration: This bug (846174) was mentioned in https://build.opensuse.org/request/show/205485 Evergreen:11.2 / jakarta-commons-fileupload
Update released for: jakarta-commons-fileupload, jakarta-commons-fileupload-javadoc Products: SLE-SERVER 11-SP3 (i386, ia64, ppc64, s390x, x86_64) SLES4VMWARE 11-SP3 (i386, x86_64)
Update released for: jakarta-commons-fileupload, jakarta-commons-fileupload-javadoc Products: SLE-SERVER 11-SP2 (i386, ia64, ppc64, s390x, x86_64) SLES4VMWARE 11-SP2 (i386, x86_64)
Update released for: jakarta-commons-fileupload, jakarta-commons-fileupload-javadoc Products: SLE-SERVER 11-SP1-TERADATA (x86_64) SUSE-MANAGER 1.2 (x86_64)
released