CVE-2013-2186
libcommons-fileupload-java - arbitrary file upload via deserialization
EPSS 12.8%
描述
The DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red Hat JBoss Web Server 1.0.2 allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance.
如何修補 CVE-2013-2186
要修補 CVE-2013-2186,請將受影響套件升級到下列已修補版本。
- Debian/libcommons-fileupload-java—升級至 1.3-2.1 或更新版本
- Debian/libcommons-fileupload-java—升級至 1.2.2-1+deb6u1 或更新版本
- —升級至 1.3.1 或更新版本
CVE-2013-2186 正在被利用嗎?
中等 — EPSS 為 12.8%,可持續追蹤但非最高優先。
受影響套件(3)
- from 0, < 1.3-2.1
- from 0, < 1.2.2-1+deb6u1
- from 0, < 1.3.1