---
title: "CVE-2011-2729\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2011-2729?format=md
keywords: index, follow
---

# CVE-2011-2729

Publication date 15 August 2011

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3
through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through
5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not
drop capabilities, which allows remote attackers to bypass read permissions
for files via a request to an application.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2011-2729?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| commons-daemon | 11.10 oneiric | Fixed 1.0.6-1ubuntu0.1 |
| 11.04 natty | Fixed 1.0.4-1ubuntu0.1 |
| 10.10 maverick | Not affected |
| 10.04 LTS lucid | Not affected |
| 8.04 LTS hardy | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2011-2729?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

tomcat isn't built with commons

---

### [jdstrand](https://launchpad.net/~jdstrand)

according to upstream, needs to be built with libcap to be affected.
Only Ubuntu 11.04 and later are built with libcap.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| commons-daemon | * Upstream:   <http://svn.apache.org/viewvc?view=revision&revision=1152701> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-2729)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2011-2729)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2011-2729)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2011-2729)

### Related Ubuntu Security Notices (USN)

+ [USN-1298-1](https://usn.ubuntu.com/USN-1298-1)
+ Apache Commons Daemon vulnerability
+ 12 December 2011

### Other references

* <http://tomcat.apache.org/security-7.html>
* <http://tomcat.apache.org/security-6.html>
* <http://tomcat.apache.org/security-5.html>
* <https://www.cve.org/CVERecord?id=CVE-2011-2729>
