Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:0730-1

Опубликовано: 14 мар. 2023
Источник: suse-cvrf

Описание

Security update for jakarta-commons-fileupload

This update for jakarta-commons-fileupload fixes the following issues:

  • CVE-2016-3092: Fixed a usage of vulnerable FileUpload package can result in denial of service (bsc#986359).
  • CVE-2023-24998: Fixed a FileUpload deny of service with excessive parts (bsc#1208513).

Список пакетов

SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS
jakarta-commons-fileupload-1.1.1-150000.4.8.1
SUSE Linux Enterprise Server 15 SP1-LTSS
jakarta-commons-fileupload-1.1.1-150000.4.8.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1
jakarta-commons-fileupload-1.1.1-150000.4.8.1
openSUSE Leap 15.4
jakarta-commons-fileupload-1.1.1-150000.4.8.1
jakarta-commons-fileupload-javadoc-1.1.1-150000.4.8.1

Описание

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:jakarta-commons-fileupload-1.1.1-150000.4.8.1
SUSE Linux Enterprise Server 15 SP1-LTSS:jakarta-commons-fileupload-1.1.1-150000.4.8.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1:jakarta-commons-fileupload-1.1.1-150000.4.8.1
openSUSE Leap 15.4:jakarta-commons-fileupload-1.1.1-150000.4.8.1

Ссылки

Описание

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP1-LTSS:jakarta-commons-fileupload-1.1.1-150000.4.8.1
SUSE Linux Enterprise Server 15 SP1-LTSS:jakarta-commons-fileupload-1.1.1-150000.4.8.1
SUSE Linux Enterprise Server for SAP Applications 15 SP1:jakarta-commons-fileupload-1.1.1-150000.4.8.1
openSUSE Leap 15.4:jakarta-commons-fileupload-1.1.1-150000.4.8.1

Ссылки