CVE-2011-2729

MEDIUM

Description

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

References

http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00024.html

http://mail-archives.apache.org/mod_mbox/commons-dev/201108.mbox/%[email protected]%3E

http://mail-archives.apache.org/mod_mbox/tomcat-announce/201108.mbox/%[email protected]%3E

http://marc.info/?l=bugtraq&m=132215163318824&w=2

http://marc.info/?l=bugtraq&m=133469267822771&w=2

http://marc.info/?l=bugtraq&m=136485229118404&w=2

http://marc.info/?l=bugtraq&m=139344343412337&w=2

http://people.apache.org/~markt/patches/2011-08-12-cve2011-2729-tc5.patch

http://secunia.com/advisories/46030

http://secunia.com/advisories/57126

http://securitytracker.com/id?1025925

http://svn.apache.org/viewvc?view=revision&revision=1152701

http://svn.apache.org/viewvc?view=revision&revision=1153379

http://svn.apache.org/viewvc?view=revision&revision=1153824

http://tomcat.apache.org/security-5.html

http://tomcat.apache.org/security-6.html

http://tomcat.apache.org/security-7.html

http://www.redhat.com/support/errata/RHSA-2011-1291.html

http://www.redhat.com/support/errata/RHSA-2011-1292.html

http://www.securityfocus.com/archive/1/519263/100/0/threaded

http://www.securityfocus.com/bid/49143

https://bugzilla.redhat.com/show_bug.cgi?id=730400

https://exchange.xforce.ibmcloud.com/vulnerabilities/69161

https://issues.apache.org/jira/browse/DAEMON-214

https://lists.apache.org/thread.html/[email protected]%3Cdev.tomcat.apache.org%3E

https://lists.apache.org/thread.html/[email protected]%3Cdev.tomcat.apache.org%3E

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14743

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19450

Details

Source: MITRE

Published: 2011-08-15

Updated: 2019-03-25

Type: CWE-264

Risk Information

CVSS v2.0

Base Score: 5

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 10

Severity: MEDIUM