CVE-2013-0248
Gentoo Linux Security Advisory 202107-39
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
La configuración por defecto de javax.servlet.context.tempdir en Apache FileUpload v1.0 hastar v1.2.2 usa el directorio /tmp para subir ficheros, lo que permite a usuarios locales sobreescribir ficheros arbitrarios mediante un ataque de enlace simbólico no especificado.
Potential security vulnerabilities have been identified with HP Matrix Operating Environment. The vulnerabilities could be exploited remotely resulting in unauthorized modification, unauthorized access, or unauthorized disclosure of information. Revision 1 of this advisory.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-12-06 CVE Reserved
- 2013-03-15 CVE Published
- 2024-08-06 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://archives.neohapsis.com/archives/bugtraq/2013-03/0035.html | Mailing List | |
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html | X_refsource_confirm |
|
http://www.osvdb.org/90906 | Vdb Entry | |
http://www.securityfocus.com/bid/58326 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://marc.info/?l=bugtraq&m=144050155601375&w=2 | 2021-07-17 | |
https://security.gentoo.org/glsa/202107-39 | 2021-07-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Commons Fileupload Search vendor "Apache" for product "Commons Fileupload" | 1.0 Search vendor "Apache" for product "Commons Fileupload" and version "1.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Commons Fileupload Search vendor "Apache" for product "Commons Fileupload" | 1.1 Search vendor "Apache" for product "Commons Fileupload" and version "1.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Commons Fileupload Search vendor "Apache" for product "Commons Fileupload" | 1.1.1 Search vendor "Apache" for product "Commons Fileupload" and version "1.1.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Commons Fileupload Search vendor "Apache" for product "Commons Fileupload" | 1.2 Search vendor "Apache" for product "Commons Fileupload" and version "1.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Commons Fileupload Search vendor "Apache" for product "Commons Fileupload" | 1.2.1 Search vendor "Apache" for product "Commons Fileupload" and version "1.2.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Commons Fileupload Search vendor "Apache" for product "Commons Fileupload" | 1.2.2 Search vendor "Apache" for product "Commons Fileupload" and version "1.2.2" | - |
Affected
|