CVE-2011-2729
published 2011-08-15CVE-2011-2729: native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30…
PriorityP434medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
7.24%
93.7th percentile
native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
Affected
28 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_commons_daemon | — | — |
| apache | apache_commons_daemon | — | — |
| apache | apache_commons_daemon | — | — |
| apache | apache_commons_daemon | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache Commons Daemon vulnerability
vendor_ubuntu·2011-12-12
CVE-2011-2729 Apache Commons Daemon vulnerability
Title: Apache Commons Daemon vulnerability
Summary: Apache Commons Daemon would allow unintended access to files over the
network.
Wilfried Weissmann discovered that Apache Commons Daemon incorrectly
dropped capabilities after starting. A remote attacker could possibly use
this flaw to read certain files, bypassing the intended permissions.
Instructions: After a standard system update you need to restart applications which use
Apache Commons Daemon, such as the Jetty web server, to make all the
necessary changes.
Red Hat
jakarta-commons-daemon: jsvc does not drop capabilities allowing access to files and directories owned by the superuser
vendor_redhat·2011-08-12·CVSS 5.0
CVE-2011-2729 [MEDIUM] jakarta-commons-daemon: jsvc does not drop capabilities allowing access to files and directories owned by the superuser
jakarta-commons-daemon: jsvc does not drop capabilities allowing access to files and directories owned by the superuser
native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
Package: jakarta-commons-daemon (Red Hat Enterprise Linux 5) - Not affected
Package: jakarta-commons-daemon (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2011-2729: commons-daemon - native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0...
vendor_debian·2011·CVSS 5.0
CVE-2011-2729 [MEDIUM] CVE-2011-2729: commons-daemon - native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0...
native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
Scope: local
bookworm: resolved (fixed in 1.0.7-1)
bullseye: resolved (fixed in 1.0.7-1)
forky: resolved (fixed in 1.0.7-1)
sid: resolved (fixed in 1.0.7-1)
trixie: resolved (fixed in 1.0.7-1)
GHSA
GHSA-7mg3-pr99-8rh7: native/unix/native/jsvc-unix
ghsa_unreviewed·2022-05-14
CVE-2011-2729 [MEDIUM] GHSA-7mg3-pr99-8rh7: native/unix/native/jsvc-unix
native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
OSV
CVE-2011-2729: native/unix/native/jsvc-unix
osv·2011-08-15·CVSS 5.0
CVE-2011-2729 [MEDIUM] CVE-2011-2729: native/unix/native/jsvc-unix
native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application.
No detection rules found.
Bugzilla
CVE-2011-2729 jakarta-commons-daemon: jsvc does not drop capabilities allowing access to files and directories owned by the superuser [fedora-15]
bugzilla·2011-08-15·CVSS 5.0
CVE-2011-2729 [MEDIUM] CVE-2011-2729 jakarta-commons-daemon: jsvc does not drop capabilities allowing access to files and directories owned by the superuser [fedora-15]
CVE-2011-2729 jakarta-commons-daemon: jsvc does not drop capabilities allowing access to files and directories owned by the superuser [fedora-15]
fedora-15 tracking bug for apache-commons-daemon: see blocks bug list for full details of the security issue(s).
This bug is never intended to be made public, please put any public notes
in the 'blocks' bugs.
[bug automatically created by: add-tracking-bugs]
Discussion:
This message is a notice that Fedora 15 is now at end of life. Fedora
has stopped maintaining and issuing updates for Fedora 15. It is
Fedora's policy to close all bug reports from releases that are no
longer maintained. At this time, all open bugs with a Fedora 'version'
of '15' have been closed as WONTFIX.
(Please note: Our normal process is to give advanced warning of th
Bugzilla
CVE-2011-2729 jakarta-commons-daemon: jsvc does not drop capabilities allowing access to files and directories owned by the superuser
bugzilla·2011-08-12·CVSS 5.0
CVE-2011-2729 [MEDIUM] CVE-2011-2729 jakarta-commons-daemon: jsvc does not drop capabilities allowing access to files and directories owned by the superuser
CVE-2011-2729 jakarta-commons-daemon: jsvc does not drop capabilities allowing access to files and directories owned by the superuser
A bug in the capabilities code of tomcat5 [1] and tomcat6 [1] was identified in jsvc (the service wrapper for Linux that is part of the Commons Daemon project). jsvc would not drop capabilities, allowing the application to access files and directories owned by the superuser. The vulnerability only occurred when the following conditions were true:
* Tomcat is running on Linux
* jsvc is compiled with libcap
* -user parameter is used
This affects Tomcat 6.0.30-6.0.32 and is fixed in r1153824 [3] and Tomcat 5.5.32-5.5.33, a proposed patch is available [4], however all these do is update the build files to use the latest Apache Commons Daemon. The real flaw is
http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00024.htmlhttp://mail-archives.apache.org/mod_mbox/commons-dev/201108.mbox/%3C4E451B2B.9090108%40apache.org%3Ehttp://mail-archives.apache.org/mod_mbox/tomcat-announce/201108.mbox/%3C4E45221D.1020306%40apache.org%3Ehttp://marc.info/?l=bugtraq&m=132215163318824&w=2http://marc.info/?l=bugtraq&m=133469267822771&w=2http://marc.info/?l=bugtraq&m=136485229118404&w=2http://marc.info/?l=bugtraq&m=139344343412337&w=2http://people.apache.org/~markt/patches/2011-08-12-cve2011-2729-tc5.patchhttp://secunia.com/advisories/46030http://secunia.com/advisories/57126http://securitytracker.com/id?1025925http://svn.apache.org/viewvc?view=revision&revision=1152701http://svn.apache.org/viewvc?view=revision&revision=1153379http://svn.apache.org/viewvc?view=revision&revision=1153824http://tomcat.apache.org/security-5.htmlhttp://tomcat.apache.org/security-6.htmlhttp://tomcat.apache.org/security-7.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1291.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1292.htmlhttp://www.securityfocus.com/archive/1/519263/100/0/threadedhttp://www.securityfocus.com/bid/49143https://bugzilla.redhat.com/show_bug.cgi?id=730400https://exchange.xforce.ibmcloud.com/vulnerabilities/69161https://issues.apache.org/jira/browse/DAEMON-214https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14743https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19450http://lists.opensuse.org/opensuse-security-announce/2011-09/msg00024.htmlhttp://mail-archives.apache.org/mod_mbox/commons-dev/201108.mbox/%3C4E451B2B.9090108%40apache.org%3Ehttp://mail-archives.apache.org/mod_mbox/tomcat-announce/201108.mbox/%3C4E45221D.1020306%40apache.org%3Ehttp://marc.info/?l=bugtraq&m=132215163318824&w=2http://marc.info/?l=bugtraq&m=133469267822771&w=2http://marc.info/?l=bugtraq&m=136485229118404&w=2http://marc.info/?l=bugtraq&m=139344343412337&w=2http://people.apache.org/~markt/patches/2011-08-12-cve2011-2729-tc5.patchhttp://secunia.com/advisories/46030http://secunia.com/advisories/57126http://securitytracker.com/id?1025925http://svn.apache.org/viewvc?view=revision&revision=1152701http://svn.apache.org/viewvc?view=revision&revision=1153379http://svn.apache.org/viewvc?view=revision&revision=1153824http://tomcat.apache.org/security-5.htmlhttp://tomcat.apache.org/security-6.htmlhttp://tomcat.apache.org/security-7.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1291.htmlhttp://www.redhat.com/support/errata/RHSA-2011-1292.htmlhttp://www.securityfocus.com/archive/1/519263/100/0/threadedhttp://www.securityfocus.com/bid/49143https://bugzilla.redhat.com/show_bug.cgi?id=730400https://exchange.xforce.ibmcloud.com/vulnerabilities/69161https://issues.apache.org/jira/browse/DAEMON-214https://lists.apache.org/thread.html/06cfb634bc7bf37af7d8f760f118018746ad8efbd519c4b789ac9c2e%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/8dcaf7c3894d66cb717646ea1504ea6e300021c85bb4e677dc16b1aa%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r3aacc40356defc3f248aa504b1e48e819dd0471a0a83349080c6bcbf%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r584a714f141eff7b1c358d4679288177bd4ca4558e9999d15867d4b5%40%3Cdev.tomcat.apache.org%3Ehttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14743https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19450
2011-08-15
Published