oval:org.mitre.oval:def:20856

Definition Id: oval:org.mitre.oval:def:20856
 
Oval ID: oval:org.mitre.oval:def:20856
Title: DSA-2827-1 libcommons-fileupload-java - arbitrary file upload via deserialization
Description: It was discovered that Apache Commons FileUpload, a package to make it easy to add robust, high-performance, file upload capability to servlets and web applications, incorrectly handled file names with NULL bytes in serialized instances. A remote attacker able to supply a serialized instance of the DiskFileItem class, which will be deserialized on a server, could use this flaw to write arbitrary content to any location on the server that is accessible to the user running the application server process.
Family: unix Class: patch
Reference(s): DSA-2827-1
CVE-2013-2186
Version: 5
Platform(s): Debian GNU/Linux 6.0
Debian GNU/Linux 7
Debian GNU/kFreeBSD 6.0
Debian GNU/kFreeBSD 7
Product(s): libcommons-fileupload-java
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:12959
 
Oval ID: oval:org.mitre.oval:def:12959
Title: Debian 6.0 is installed
Description: Debian 6.0 (squeeze) is installed
Family: unix Class: inventory
Reference(s): cpe:/o:debian:debian:6.0
Version: 6
Platform(s): Debian 6.0
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:20856
Definition Id: oval:org.mitre.oval:def:19338
 
Oval ID: oval:org.mitre.oval:def:19338
Title: Debian 7 is installed
Description: Debian 7 (wheezy) is installed
Family: unix Class: inventory
Reference(s): cpe:/o:debian:debian:7
Version: 7
Platform(s): Debian 7
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:20856
Definition Id: oval:org.mitre.oval:def:24698
 
Oval ID: oval:org.mitre.oval:def:24698
Title: Debian GNU/kFreeBSD is installed
Description: Debian GNU/kFreeBSD is installed
Family: unix Class: inventory
Reference(s): cpe:/o:debian:debian_gnu/kfreebsd
Version: 3
Platform(s): Debian GNU/kFreeBSD
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:20856
oval:org.mitre.oval:def:20856
Definition Id: oval:org.mitre.oval:def:24894
 
Oval ID: oval:org.mitre.oval:def:24894
Title: Debian GNU/Linux is installed
Description: Debian GNU/Linux is installed
Family: unix Class: inventory
Reference(s): cpe:/o:debian:debian_gnu/linux
Version: 3
Platform(s): Debian GNU/Linux
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:20856
oval:org.mitre.oval:def:20856