Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2025:02184-1

Опубликовано: 01 июл. 2025
Источник: suse-cvrf

Описание

Security update for jakarta-commons-fileupload

This update for jakarta-commons-fileupload fixes the following issues:

Upgrade to upstream version 1.6.0

  • CVE-2025-48976: Fixed allocation of resources for multipart headers with insufficient limits can lead to a DoS (bsc#1244657).

Full changelog:

https://commons.apache.org/proper/commons-fileupload/changes.html#a1.6.0

Список пакетов

SUSE Linux Enterprise Server 12 SP5-LTSS
jakarta-commons-fileupload-1.6.0-126.3.1
jakarta-commons-fileupload-javadoc-1.6.0-126.3.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
jakarta-commons-fileupload-1.6.0-126.3.1
jakarta-commons-fileupload-javadoc-1.6.0-126.3.1

Описание

Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5-LTSS:jakarta-commons-fileupload-1.6.0-126.3.1
SUSE Linux Enterprise Server 12 SP5-LTSS:jakarta-commons-fileupload-javadoc-1.6.0-126.3.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:jakarta-commons-fileupload-1.6.0-126.3.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5:jakarta-commons-fileupload-javadoc-1.6.0-126.3.1

Ссылки