Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:0758-1

Опубликовано: 16 мар. 2023
Источник: suse-cvrf

Описание

Security update for jakarta-commons-fileupload

This update for jakarta-commons-fileupload fixes the following issues:

  • CVE-2016-3092: Fixed a usage of vulnerable FileUpload package can result in denial of service (bsc#986359).
  • CVE-2023-24998: Fixed a FileUpload deny of service with excessive parts (bsc#1208513).

Список пакетов

SUSE Linux Enterprise Server 12 SP2-BCL
jakarta-commons-fileupload-1.1.1-122.8.1
jakarta-commons-fileupload-javadoc-1.1.1-122.8.1
SUSE Linux Enterprise Server 12 SP4-ESPOS
jakarta-commons-fileupload-1.1.1-122.8.1
jakarta-commons-fileupload-javadoc-1.1.1-122.8.1
SUSE Linux Enterprise Server 12 SP4-LTSS
jakarta-commons-fileupload-1.1.1-122.8.1
jakarta-commons-fileupload-javadoc-1.1.1-122.8.1
SUSE Linux Enterprise Server 12 SP5
jakarta-commons-fileupload-1.1.1-122.8.1
jakarta-commons-fileupload-javadoc-1.1.1-122.8.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
jakarta-commons-fileupload-1.1.1-122.8.1
jakarta-commons-fileupload-javadoc-1.1.1-122.8.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5
jakarta-commons-fileupload-1.1.1-122.8.1
jakarta-commons-fileupload-javadoc-1.1.1-122.8.1
SUSE OpenStack Cloud 9
jakarta-commons-fileupload-1.1.1-122.8.1
jakarta-commons-fileupload-javadoc-1.1.1-122.8.1
SUSE OpenStack Cloud Crowbar 9
jakarta-commons-fileupload-1.1.1-122.8.1
jakarta-commons-fileupload-javadoc-1.1.1-122.8.1

Описание

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:jakarta-commons-fileupload-1.1.1-122.8.1
SUSE Linux Enterprise Server 12 SP2-BCL:jakarta-commons-fileupload-javadoc-1.1.1-122.8.1
SUSE Linux Enterprise Server 12 SP4-ESPOS:jakarta-commons-fileupload-1.1.1-122.8.1
SUSE Linux Enterprise Server 12 SP4-ESPOS:jakarta-commons-fileupload-javadoc-1.1.1-122.8.1

Ссылки

Описание

Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be explicitly configured.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP2-BCL:jakarta-commons-fileupload-1.1.1-122.8.1
SUSE Linux Enterprise Server 12 SP2-BCL:jakarta-commons-fileupload-javadoc-1.1.1-122.8.1
SUSE Linux Enterprise Server 12 SP4-ESPOS:jakarta-commons-fileupload-1.1.1-122.8.1
SUSE Linux Enterprise Server 12 SP4-ESPOS:jakarta-commons-fileupload-javadoc-1.1.1-122.8.1

Ссылки