Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 10.04 LTS USN-2029-1 Critical: File Overwrite in Apache Commons

ubuntu
Calendar Grey November 13, 2013
Scroller Ubuntu
Important Apache Commons FileUpload vulnerability detected in Ubuntu, permitting file overwrites. Immediate updates required for security!
Apache Commons FileUpload could be made to overwrite files.

Summary

Apache Commons FileUpload could be made to overwrite files.

Software Description:

- libcommons-fileupload-java: File upload capability for servlets and web

applications

Details:

It was discovered that Apache Commons FileUpload incorrectly handled file

names with NULL bytes in serialized instances. An attacker could use this

issue to possibly write to arbitrary files.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 10.04 LTS:
  libcommons-fileupload-java      1.2.1-3ubuntu2.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2029-1

CVE-2013-2186

Severity
critical
Lowest
Low
Medium
High
Critical

November 13, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.