CVE-2013-0248 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0248): The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack. Upstream fixed in 1.3
*commons-fileupload-1.3 (20 Apr 2013) 20 Apr 2013; Ralph Sennhauser <sera@gentoo.org> +files/0001-Remove-bogous-manifest-entry.patch, +files/0002-Fix-running-tests.patch, +commons-fileupload-1.3.ebuild: Security bump. #466460 =dev-java/commons-fileupload-1.3 ... needs to be stabilized for amd64 ppc ppc64 and x86. Thanks.
amd64 stable
x86 stable
ppc stable
ppc64 stable
Thanks for your work GLSA vote: no
GLSA vote: no. Closing noglsa.