CVE-2011-2729

Publication date 15 August 2011

Last updated 24 July 2024


Ubuntu priority

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

Read the notes from the security team

Status

Package Ubuntu Release Status
commons-daemon 11.10 oneiric
Fixed 1.0.6-1ubuntu0.1
11.04 natty
Fixed 1.0.4-1ubuntu0.1
10.10 maverick
Not affected
10.04 LTS lucid
Not affected
8.04 LTS hardy Ignored end of life

Notes


mdeslaur

tomcat isn't built with commons


jdstrand

according to upstream, needs to be built with libcap to be affected. Only Ubuntu 11.04 and later are built with libcap.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
commons-daemon