Summary: | dev-java/commons-fileupload: Multiple vulnerabilities (CVE-2013-0248, CVE-2014-0050, CVE-2016-3092) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Sam James <sam> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | fordfrog, java |
Priority: | Normal | Keywords: | PMASKED |
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://commons.apache.org/proper/commons-fileupload/security-reports.html#Apache_Commons_FileUpload_Security_Vulnerabilities | ||
See Also: |
https://bugs.gentoo.org/show_bug.cgi?id=500600 https://bugs.gentoo.org/show_bug.cgi?id=586966 |
||
Whiteboard: | B3 [glsa+ cve] | ||
Package list: | Runtime testing required: | --- |
Description
Sam James
2020-08-28 03:23:26 UTC
Given "FILEUPLOAD-279: DiskFileItem can no longer be deserialized, unless a particular system property is set." in the release notes [0], it may be better to just bump to 1.3.3 or even 1.4.x(?) [0] https://dist.apache.org/repos/dist/release/commons/fileupload/RELEASE-NOTES.txt The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=4f74b87959645481a244bc4513bcee58ea74e663 commit 4f74b87959645481a244bc4513bcee58ea74e663 Author: Jakov Smolic <jakov.smolic@sartura.hr> AuthorDate: 2021-05-26 09:05:10 +0000 Commit: Sam James <sam@gentoo.org> CommitDate: 2021-05-26 12:33:33 +0000 dev-java/commons-fileupload: Remove last-rited pkg Closes: https://bugs.gentoo.org/736577 Bug: https://bugs.gentoo.org/739350 Closes: https://bugs.gentoo.org/785847 Signed-off-by: Jakov Smolic <jakov.smolic@sartura.hr> Signed-off-by: Sam James <sam@gentoo.org> dev-java/commons-fileupload/Manifest | 1 - .../commons-fileupload-1.3.ebuild | 57 ---------------------- .../files/0001-Remove-bogous-manifest-entry.patch | 29 ----------- .../files/0002-Fix-running-tests.patch | 25 ---------- dev-java/commons-fileupload/metadata.xml | 19 -------- profiles/package.mask | 6 --- 6 files changed, 137 deletions(-) GLSA request filed. This issue was resolved and addressed in GLSA 202107-39 at https://security.gentoo.org/glsa/202107-39 by GLSA coordinator John Helmert III (ajak). |