[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 528-1] libcommons-fileupload-java security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Package        : libcommons-fileupload-java
Version        : 1.2.2-1+deb7u3
CVE ID         : CVE-2016-3092


A denial of service vulnerability was identified in Commons FileUpload
that occurred when the length of the multipart boundary was just below
the size of the buffer (4096 bytes) used to read the uploaded file.
This caused the file upload process to take several orders of
magnitude longer than if the boundary was the typical tens of bytes long.

For Debian 7 "Wheezy", these problems have been fixed in version
1.2.2-1+deb7u3.

We recommend that you upgrade your libcommons-fileupload-java packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQJ8BAEBCgBmBQJXcCTsXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRBQ0YzRDA4OEVGMzJFREVGNkExQTgzNUZE
OUFEMTRCOTUxM0I1MUU0AAoJENmtFLlRO1HkQL4P/iOzpYyVFRowQRKWbK7qzNuP
h6cc8NLKsXFS7vfSYGiwyCUrB2RSBnWubG8XTszjPRYmEXrvrbrg1GBQksE8MKT5
Av5HAwQ/VQ8uSwl5Qwqy5Tf62svYw5tgEJ9AHfNrTS55irML/2hUHODMrGQb3GD3
el5fzS+3Od50duPYhXIk/ZbErotlZkurhzLE32fG9GRcS/AkgLfOEhXycuVXogSH
aU9vgdUAQySnKF+fp9QWYPCaOw6VtOWrsKS5lt1kvNaL26W2Idgjabul41a9wpTt
gSstOjKWP1gwKEV7rNGiQboSQ8X1gHorBsTjSigKgEQUeeE2A2w4kFxWp7Q4jGwV
oZkUXgd9SZ2D0aKWMtWopdo9gK3Vbm+G61yRpZi9NWRyru5d0Txpjg7SHYujA2Ao
B75bX1W2RL4DdT24BXgpo2i1Hsf/KmpxhzY1elR5LmcHfjPZMsze08BSxymdcL5k
HXS+m586TwbwcZ3Jd832ifPgbPHFb4aRFyQgBE7ZvZuoWUN7fi33LAvQ73iiyt9/
OIpfbJ6+Q2NVOhRNuY9NSYMGaVv1BI7vsjla4XfxJa/2OZkNH6OACEx7vSNmI0NL
eGpG3mNlM/Tg1eUCWTx2or+rDAmiVDFemg5bX/mmTpDM7Ao285NLUklz2vhq1TZU
gt88W/kxLoiq7qsdg0FR
=7wlb
-----END PGP SIGNATURE-----


Reply to: