SuSE: 2013:1660-1: important: jakarta-commons-fileupload
Summary
jakarta-commons-fileupload received a security fix:
* A poison null byte flaw was found in the
implementation of the DiskFileItem class. A remote attacker
could able to supply a serialized instance of the
DiskFileItem class, which would be deserialized on a
server, could use this flaw to write arbitrary content to
any location on the server that is permitted by the user
running the application server process. (CVE-2013-2186)
Security Issue reference:
* CVE-2013-2186
References
#846174
Cross- CVE-2013-2186
Affected Products:
SUSE Linux Enterprise Server 11 SP3 for VMware
SUSE Linux Enterprise Server 11 SP3
SUSE Linux Enterprise Server 11 SP2 for VMware
SUSE Linux Enterprise Server 11 SP2
https://www.suse.com/security/cve/CVE-2013-2186.html
https://bugzilla.novell.com/846174
https://login.microfocus.com/nidp/app/login
https://login.microfocus.com/nidp/app/login