CVE-2011-2729
EPSS 7.2%
Description
native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
How to fix CVE-2011-2729
To remediate CVE-2011-2729, upgrade the affected package to a fixed version below.
- Debian/commons-daemon—upgrade to 1.0.7-1 or later
Is CVE-2011-2729 being exploited?
Moderate — EPSS is 7.2%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 1.0.7-1