CVE-2014-0050
libcommons-fileupload-java - security update
EPSS 83.2%
描述
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
如何修補 CVE-2014-0050
要修補 CVE-2014-0050,請將受影響套件升級到下列已修補版本。
- Debian/libcommons-fileupload-java—升級至 1.3.1-1 或更新版本
- Debian/libcommons-fileupload-java—升級至 1.2.2-1+deb6u2 或更新版本
- —升級至 1.3.1 或更新版本
- —升級至 8.0.3 或更新版本
CVE-2014-0050 正在被利用嗎?
可能 — EPSS 為 83.2%,屬於高被利用機率區間,建議優先修補。
受影響套件(4)
- from 0, < 1.3.1-1
- from 0, < 1.2.2-1+deb6u2
- from 0, < 1.3.1
- >= 8.0.0-RC1, < 8.0.3