Debian Linux Security Advisory 3614-1 - The TERASOLUNA Framework Development Team discovered a denial of service vulnerability in Apache Commons FileUpload, a package to make it easy to add robust, high-performance, file upload capability to servlets and web applications. A remote attacker can take advantage of this flaw by sending file upload requests that cause the HTTP server using the Apache Commons Fileupload library to become unresponsive, preventing the server from servicing other requests.
8dbdb645982cfd7d0be2c190d07143c9f61b91668bd2ea676e951e673b8b3ff3
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-3614-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
July 02, 2016 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : tomcat7
CVE ID : CVE-2016-3092
The TERASOLUNA Framework Development Team discovered a denial of service
vulnerability in Apache Commons FileUpload, a package to make it
easy to add robust, high-performance, file upload capability to servlets
and web applications. A remote attacker can take advantage of this flaw
by sending file upload requests that cause the HTTP server using the
Apache Commons Fileupload library to become unresponsive, preventing the
server from servicing other requests.
Apache Tomcat uses a package renamed copy of Apache Commons FileUpload
to implement the file upload requirements of the Servlet specification
and is therefore also vulnerable to the denial of service vulnerability.
For the stable distribution (jessie), this problem has been fixed in
version 7.0.56-3+deb8u3.
For the testing distribution (stretch), this problem has been fixed
in version 7.0.70-1.
For the unstable distribution (sid), this problem has been fixed in
version 7.0.70-1.
We recommend that you upgrade your tomcat7 packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCgAGBQJXd7YhAAoJEAVMuPMTQ89Emg0P/2K7qVBmKMDG93HhWe2e5QXk
I748PwHm7uHV5qrIYGS8n1LDhqNxOyMaGVJdHzJAvuOJYOVsq2RXLXAhNSNZLPgr
mrOCB6i6u1ogY9ztsQi5zprhl6v0AINpQA1pP30COmiS/QlUUbGV09Z952Gg/d25
JDEpvkDmiknAKySP8Jm3GjqhYnJdyOnkRpT/PyJCfepBFk2ToR0HHOPw7kSxkCFV
SM8E0ljjrZZVKQ5SRD18egi5VjnV7R/pm+MuejfdtdA+eA/UsrUeQH0kVWNN8LUP
Hfry2Dz11tAi8WfdP9nc4cPm9m1XLG4S64J3ZwwUNzyuxYXpkyzKIViQDuO4WHMR
vKZpUjYuRcSGqySdhN2HdYxgZET3avO20tN39+iH2ASuv5LDZJ6tOQXX713+Xox1
988nMEDkxIWbgPgfIhEhPIRoW8efEAczHoY80XxjAPJF9PokCqN5OjFBQPS60D3z
zycu8+Hrxlx3C8emkVElDaFeyTmWYrMxJ/yEBEN+m0dhMdbzcwlXTAtLgrXkQUga
Ly8RmMpougmN0Kx0CqCwYKyxzn7peSi2LP90gfHu5etks3rtN122c2R69Ma1DbXh
mEMj0K9R2qjKFJeZ9fIU7Gxx9+Wo0dJnlEMc3jL2Ne36HBrcP3fQuKnQxw2lWbaP
yL3atzZ13OmvyxAJltuN
=RBqU
-----END PGP SIGNATURE-----