packetstorm_rss ([info]packetstorm_rss) rakstīja,
@ 2013-12-24 16:38:00

Previous Entry  Add to memories!  Tell a Friend!  Next Entry
Debian Security Advisory 2827-1
Debian Linux Security Advisory 2827-1 - It was discovered that Apache Commons FileUpload, a package to make it easy to add robust, high-performance, file upload capability to servlets and web applications, incorrectly handled file names with NULL bytes in serialized instances. A remote attacker able to supply a serialized instance of the DiskFileItem class, which will be deserialized on a server, could use this flaw to write arbitrary content to any location on the server that is accessible to the user running the application server process.


Neesi iežurnalējies. Iežurnalēties?