CVE Vulnerabilities

CVE-2011-2729

Published: Aug 15, 2011 | Modified: Apr 29, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
5.8 IMPORTANT
AV:N/AC:M/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

Affected Software

NameVendorStart VersionEnd Version
Apache_commons_daemonApache1.0.3 (including)1.0.3 (including)
Apache_commons_daemonApache1.0.4 (including)1.0.4 (including)
Apache_commons_daemonApache1.0.5 (including)1.0.5 (including)
Apache_commons_daemonApache1.0.6 (including)1.0.6 (including)
TomcatApache5.5.32 (including)5.5.32 (including)
TomcatApache5.5.33 (including)5.5.33 (including)
Red Hat JBoss Enterprise Web Server 1RedHat*
Commons-daemonUbuntuhardy*
Commons-daemonUbuntunatty*
Commons-daemonUbuntuoneiric*
Commons-daemonUbuntuupstream*

References