Описание
Security update for jakarta-commons-fileupload
This update for jakarta-commons-fileupload fixes the following issues:
- CVE-2016-3092: Fixed a usage of vulnerable FileUpload package can result in denial of service (bsc#986359).
- CVE-2023-24998: Fixed a FileUpload deny of service with excessive parts (bsc#1208513).
Список пакетов
SUSE Linux Enterprise Server 12 SP2-BCL
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE Linux Enterprise Server 12 SP4-LTSS
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server for SAP Applications 12 SP4
SUSE Linux Enterprise Server for SAP Applications 12 SP5
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 9
Ссылки
- Link for SUSE-SU-2023:0758-1
- E-Mail link for SUSE-SU-2023:0758-1
- SUSE Security Ratings
- SUSE Bug 1208513
- SUSE Bug 986359
- SUSE CVE CVE-2016-3092 page
- SUSE CVE CVE-2023-24998 page
Описание
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
Затронутые продукты
Ссылки
- CVE-2016-3092
- SUSE Bug 1068865
- SUSE Bug 986359
- SUSE Bug 988489
Описание
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.
Затронутые продукты
Ссылки
- CVE-2023-24998
- SUSE Bug 1208513
- SUSE Bug 1210310
- SUSE Bug 1211608
- SUSE Bug 1228313