CVE-2013-0248
Publication date 15 March 2013
Last updated 24 July 2024
Ubuntu priority
The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
Status
Package | Ubuntu Release | Status |
---|---|---|
libcommons-fileupload-java | ||
Notes
mdeslaur
version 1.3 added documentation notes that a directory should be specified when using the API. this isn't worth fixing in stable releases