LWN.net Logo

apache-commons-daemon: remote access to superuser files/directories

Package(s):apache-commons-daemon CVE #(s):CVE-2011-2729
Created:August 29, 2011 Updated:December 12, 2011
Description: From the CVE entry:

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

Alerts:
Ubuntu USN-1298-1 2011-12-12
openSUSE openSUSE-SU-2011:1062-1 2011-09-23
Fedora FEDORA-2011-10936 2011-08-17
Gentoo 201206-24 2012-06-24

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds