VDB

DEBIAN-CVE-2011-2729

DEBIAN-CVE-2011-2729 PUBLISHED

native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.

Affected Products

VendorProductVersions
Debian:14commons-daemon0, 0, 0
Debian:12commons-daemon0, 0, 0
Debian:11commons-daemon0, 0, 0
Debian:13commons-daemon0, 0, 0

Timeline

  • Aug 15, 2011 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›