Lucene search

K
ubuntuUbuntuUSN-2029-1
HistoryNov 13, 2013 - 12:00 a.m.

Apache Commons FileUpload vulnerability

2013-11-1300:00:00
ubuntu.com
45

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.6 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.6%

Releases

  • Ubuntu 10.04

Packages

  • libcommons-fileupload-java - File upload capability for servlets and web applications

Details

It was discovered that Apache Commons FileUpload incorrectly handled file
names with NULL bytes in serialized instances. An attacker could use this
issue to possibly write to arbitrary files.

OSVersionArchitecturePackageVersionFilename
Ubuntu10.04noarchlibcommons-fileupload-java< 1.2.1-3ubuntu2.1UNKNOWN

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.6 High

AI Score

Confidence

High

0.019 Low

EPSS

Percentile

88.6%