All errata/sisyphus/ALT-PU-2016-3250-2
ALT-PU-2016-3250-2

Package update apache-commons-fileupload in branch sisyphus

Version1.3.2-alt1_1jpp8
Published2026-02-04
Max severityHIGH
Severity:

Closed issues (3)

BDU:2016-01698
HIGH7.3

Уязвимость библиотеки Сommons FileUpload, позволяющая нарушителю вызвать отказ в обслуживании

Published: 2016-07-19Modified: 2025-10-07
CVSS 3.xHIGH 7.3
CVSS:3.x/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS 2.0HIGH 7.8
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:C
CVE-2016-3092
HIGH7.5

The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.

Published: 2016-07-04Modified: 2025-04-12
CVSS 2.0HIGH 7.8
CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:N/A:C
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
GHSA-fvm3-cfvj-gxqq
HIGH7.5

High severity vulnerability that affects commons-fileupload:commons-fileupload

Published: 2018-12-21Modified: 2021-07-19
CVSS 3.xHIGH 7.5
CVSS:3.x/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References