GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sat Jul 17, 2021 6:26 am Post subject: [ GLSA 202107-39 ] Apache Commons FileUpload |
|
|
Gentoo Linux Security Advisory
Title: Apache Commons FileUpload: Multiple vulnerabilities (GLSA 202107-39)
Severity: low
Exploitable: remote
Date: 2021-07-17
Bug(s): #739350
ID: 202107-39
Synopsis
Multiple vulnerabilities have been found in Apache Commons
FileUpload, the worst of which could result in a Denial of Service
condition.
Background
The Apache Commons FileUpload package makes it easy to add robust,
high-performance, file upload capability to your servlets and web
applications.
Affected Packages
Package: dev-java/commons-fileupload
Vulnerable: <= 1.3
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Apache Commons
FileUpload. Please review the CVE identifiers referenced below for
details.
Impact
Please review the referenced CVE identifiers for details.
Workaround
There is no known workaround at this time.
Resolution
Gentoo has discontinued support for Apache Commons FileUpload. We
recommend that users unmerge it:
Code: | # emerge --ask --depclean "dev-java/commons-fileupload"
| NOTE: The Gentoo developer(s) maintaining Apache Commons FileUpload have
discontinued support at this time. It may be possible that a new Gentoo
developer will update Apache Commons FileUpload at a later date. We do
not have a suggestion for a replacement at this time.
References
CVE-2013-0248
CVE-2014-0050
CVE-2016-3092
Last edited by GLSA on Sat Jan 22, 2022 5:11 am; edited 2 times in total |
|