PT-2011-4045 · Apache+1 · Apache Tomcat+2

Wilfried Weissmann

·

Published

2011-08-15

·

Updated

2024-06-15

·

CVE-2011-2729

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Commons Daemon jsvc versions 1.0.3 through 1.0.6 Apache Tomcat versions 5.5.32 through 5.5.33 Apache Tomcat versions 6.0.30 through 6.0.32 Apache Tomcat versions 7.0.x before 7.0.20
Description The issue arises from a bug in the capabilities code of jsvc, which is part of the Commons Daemon project and used in Apache Tomcat. This bug prevents jsvc from dropping capabilities, allowing remote attackers to bypass read permissions for files via a request to an application. The vulnerability is specific to Tomcat running on a Linux operating system, where jsvc was compiled with the libcap parameter, and the -user parameter is used.
Recommendations For Apache Commons Daemon jsvc versions 1.0.3 through 1.0.6, update to a version that includes the fix for the capabilities code bug. For Apache Tomcat versions 5.5.32 through 5.5.33, update to a version that includes the fixed jsvc. For Apache Tomcat versions 6.0.30 through 6.0.32, update to a version that includes the fixed jsvc. For Apache Tomcat versions 7.0.x before 7.0.20, update to version 7.0.20 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-2729
HPSBUX02725
HPSBUX02860
OPENSUSE-SU-2024:10167-1
RHSA-2011:1292

Affected Products

Apache Commons Daemon
Apache Tomcat
Hp-Ux