CVE-2014-0050
libcommons-fileupload-java - security update
EPSS 92.7%
Description
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
How to fix CVE-2014-0050
To remediate CVE-2014-0050, upgrade the affected package to a fixed version below.
- Debian/libcommons-fileupload-java—upgrade to 1.3.1-1 or later
- Debian/libcommons-fileupload-java—upgrade to 1.2.2-1+deb6u2 or later
- —upgrade to 1.3.1 or later
- —upgrade to 8.0.3 or later
Is CVE-2014-0050 being exploited?
Likely — EPSS is 92.7%, placing CVE-2014-0050 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (4)
- from 0, < 1.3.1-1
- from 0, < 1.2.2-1+deb6u2
- from 0, < 1.3.1
- >= 8.0.0-RC1, < 8.0.3