CVE Vulnerabilities

CVE-2011-2729

Published: Aug 15, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
5.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

Affected Software

NameVendorStart VersionEnd Version
Apache_commons_daemonApache1.0.3 (including)1.0.3 (including)
Apache_commons_daemonApache1.0.4 (including)1.0.4 (including)
Apache_commons_daemonApache1.0.5 (including)1.0.5 (including)
Apache_commons_daemonApache1.0.6 (including)1.0.6 (including)
TomcatApache5.5.32 (including)5.5.32 (including)
TomcatApache5.5.33 (including)5.5.33 (including)
JBEWS 1.0 for RHEL 4RedHatjakarta-commons-daemon-jsvc-1:1.0.5-1.5.patch01.ep5.el4*
Red Hat JBoss Enterprise Web Server 1RedHat*
Commons-daemonUbuntuhardy*
Commons-daemonUbuntunatty*
Commons-daemonUbuntuoneiric*
Commons-daemonUbuntuupstream*

References