CVE-2011-2729
Publication date 15 August 2011
Last updated 24 July 2024
Ubuntu priority
native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
Status
Package | Ubuntu Release | Status |
---|---|---|
commons-daemon | ||
Notes
Patch details
Package | Patch details |
---|---|
commons-daemon |
References
Related Ubuntu Security Notices (USN)
- USN-1298-1
- Apache Commons Daemon vulnerability
- 12 December 2011