Login
Newsletter
Werbung

Sicherheit: Mehrere Probleme in Apache Commons FileUpload
Aktuelle Meldungen Distributionen
Name: Mehrere Probleme in Apache Commons FileUpload
ID: 202107-39
Distribution: Gentoo
Plattformen: Keine Angabe
Datum: So, 18. Juli 2021, 00:05
Referenzen: https://nvd.nist.gov/vuln/detail/CVE-2013-0248
https://nvd.nist.gov/vuln/detail/CVE-2014-0050
https://nvd.nist.gov/vuln/detail/CVE-2016-3092
Applikationen: Apache Commons FileUpload

Originalnachricht


--aht87qZ3lT3PL3Gb
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202107-39
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Severity: Low
Title: Apache Commons FileUpload: Multiple vulnerabilities
Date: July 17, 2021
Bugs: #739350
ID: 202107-39

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been found in Apache Commons FileUpload,
the worst of which could result in a Denial of Service condition.

Background
==========

The Apache Commons FileUpload package makes it easy to add robust,
high-performance, file upload capability to your servlets and web
applications.

Affected packages
=================

-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 dev-java/commons-fileupload
<= 1.3 Vulnerable!
-------------------------------------------------------------------
NOTE: Certain packages are still vulnerable. Users should migrate
to another package if one is available or wait for the
existing packages to be marked stable by their
architecture maintainers.

Description
===========

Multiple vulnerabilities have been discovered in Apache Commons
FileUpload. Please review the CVE identifiers referenced below for
details.

Impact
======

Please review the referenced CVE identifiers for details.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

Gentoo has discontinued support for Apache Commons FileUpload. We
recommend that users unmerge it:

# emerge --ask --depclean "dev-java/commons-fileupload"

NOTE: The Gentoo developer(s) maintaining Apache Commons FileUpload
have discontinued support at this time. It may be possible that a new
Gentoo developer will update Apache Commons FileUpload at a later date.
We do not have a suggestion for a replacement at this time.

References
==========

[ 1 ] CVE-2013-0248
https://nvd.nist.gov/vuln/detail/CVE-2013-0248
[ 2 ] CVE-2014-0050
https://nvd.nist.gov/vuln/detail/CVE-2014-0050
[ 3 ] CVE-2016-3092
https://nvd.nist.gov/vuln/detail/CVE-2016-3092

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

https://security.gentoo.org/glsa/202107-39

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.

License
=======

Copyright 2021 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

https://creativecommons.org/licenses/by-sa/2.5


--aht87qZ3lT3PL3Gb
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEElFuPenBj6NvNLoABXP0dAeB+IzgFAmDyZocACgkQXP0dAeB+
IzglTBAAlgy9lUywsH+cgZ9vDC3s8MMDBmkXFkTxYEvNHjE0avI/J9GCs7tzcxwa
OEqMmSl5LVgMQQvTK26joZUE+eEpD0soOzkgH61U1qbbjuXjkYJT+Al0s7tsnUK3
6hCNhyUQWosbNNwQelTvjNwTAIL2cq8LQmvLqos2AyVf6o7RnjNSz/xVCe3krFkW
brlx2Q+tdHzh1YPhJjJrSvlgmqEtAs7djdfUZiBcggwY5yxw38wZhI5ou7qL07hB
a4za4W84TN6TOB0jXihAVMce5OFNOejbHS1AF67H12sNPeFdOxtymrtF4AOXiz13
CLTjEFVF75BLohc5SlAnAsNZIHJ//sOs3DKtAe/8qGie73yAI9r2d09Q2CV6CLfj
RO3vB46HtsJ9t7mqUUgYGhg+FsrYvfzU/zyk7Ggs9h0cych3wGjwOfbiI88E2+Sz
NIimhrD6SlzUZGflXd8vsKg6JcTist/YO1cv2FPk0fPf/Oa0mQ+BMDcqEc5DKfEW
NI15ZHJG6FaaJx0ikXQem7XxNulDHgKb7tbq9pvLN5WKtQyJ13+HZxBIJVJRI8CW
+T+CPoIMJQszg3Ogcq8XhSoxxPbeo99fHRUScoy7QnVAH1UOHaEVAkPrTo7QvFfv
r0BA0M9bpYHTirBO89Zsx1irnS0yX0QLCVsM0MrEhbFX1Lrftk8=
=dKhY
-----END PGP SIGNATURE-----

--aht87qZ3lT3PL3Gb--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung