CVE-2016-3092
published 2016-07-04CVE-2016-3092: The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x…
PriorityP348high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
35.93%
98.3th percentile
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
Affected
99 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | commons_fileupload | <= 1.3.1 | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
ghsa7.5HIGH
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Knowledge Risk Matrix: Web Applications - InfoCenter (Apache Commons Fileupload) — CVE-2016-3092
vendor_oracle·2020-04-15·CVSS 7.5
CVE-2016-3092 [HIGH] Oracle Oracle Knowledge Risk Matrix: Web Applications - InfoCenter (Apache Commons Fileupload) — CVE-2016-3092
Oracle Oracle Knowledge Risk Matrix: Web Applications - InfoCenter (Apache Commons Fileupload) vulnerability
CVE: CVE-2016-3092
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2020 (APR 2020)
Jenkins
Jenkins Security Advisory 2017-10-11
vendor_jenkins·2017-10-11·CVSS 7.5
CVE-2012-6153 [HIGH] Jenkins Security Advisory 2017-10-11
Title: Jenkins Security Advisory 2017-10-11
Jenkins Security Advisory 2017-10-11
This advisory announces multiple vulnerabilities in Jenkins (weekly and LTS), and these plugins:
Maven Plugin
Swarm Plugin Client
Speaks! Plugin
Description
Arbitrary shell command execution on controller by users with Agent-related permissions
SECURITY-478 / CVE-2017-1000393
Users with permission to create or configure agents in Jenkins could configure a launch method called Launch agent via execution of command on master .
This allowed them to run arbitrary shell commands on the Jenkins controller whenever the agent was supposed to be launched.
Configuration of this launch method now requires the Run Scripts permission typically only granted t
Red Hat
jenkins: Jenkins core bundled vulnerable version of the commons-fileupload library (SECURITY-490)
vendor_redhat·2017-10-11·CVSS 7.5
CVE-2017-1000394 [HIGH] CWE-400 jenkins: Jenkins core bundled vulnerable version of the commons-fileupload library (SECURITY-490)
jenkins: Jenkins core bundled vulnerable version of the commons-fileupload library (SECURITY-490)
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.
Package: jenkins (Red Hat OpenShift Enterprise 3) - Not affected
Ubuntu
Tomcat vulnerability
vendor_ubuntu·2016-07-06
CVE-2016-3092 Tomcat vulnerability
Title: Tomcat vulnerability
Summary: Tomcat could be made to hang if it received specially crafted network
traffic.
It was discovered that the Tomcat Fileupload library incorrectly handled
certain upload requests. A remote attacker could possibly use this issue to
cause a denial of service.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2016-07-05·CVSS 4.3
CVE-2015-5174 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly handled pathnames used by web
applications in a getResource, getResourceAsStream, or getResourcePaths
call. A remote attacker could use this issue to possibly list a parent
directory . This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and
Ubuntu 15.10. (CVE-2015-5174)
It was discovered that the Tomcat mapper component incorrectly handled
redirects. A remote attacker could use this issue to determine the
existence of a directory. This issue only affected Ubuntu 12.04 LTS,
Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-5345)
It was discovered that Tomcat incorrectly handled different session
settings when multiple versions of the same web application was
Red Hat
tomcat: Usage of vulnerable FileUpload package can result in denial of service
vendor_redhat·2016-06-21·CVSS 7.5
CVE-2016-3092 [HIGH] CWE-20 tomcat: Usage of vulnerable FileUpload package can result in denial of service
tomcat: Usage of vulnerable FileUpload package can result in denial of service
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
A denial of service vulnerability was identified in Commons FileUpload that occurred when the length of the multipart boundary was just below the size of the buffer (4096 bytes) used to read the uploaded file if the boundary was the typical tens of bytes long.
Package: tomcat5 (Red Hat Enterprise Linux 5) - Not affected
Package: tomcat6 (Red Hat Enterprise Linux 6) - Not affected
Package: jbossweb (Red Hat JBoss Data
Debian
CVE-2016-3092: libcommons-fileupload-java - The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in ...
vendor_debian·2016·CVSS 7.5
CVE-2016-3092 [HIGH] CVE-2016-3092: libcommons-fileupload-java - The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in ...
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
Scope: local
bookworm: resolved (fixed in 1.3.2-1)
bullseye: resolved (fixed in 1.3.2-1)
forky: resolved (fixed in 1.3.2-1)
sid: resolved (fixed in 1.3.2-1)
trixie: resolved (fixed in 1.3.2-1)
Apache
Apache tomcat: CVE-2016-3092
vendor_apache·CVSS 7.5
CVE-2016-3092 [HIGH] Apache tomcat: CVE-2016-3092
Apache tomcat: CVE-2016-3092
Apache Tomcat uses a package renamed copy of Apache Commons FileUpload to implement the file upload requirements of the Servlet specification. A denial of service vulnerability was identified in Commons FileUpload that occurred when the length of the multipart boundary was just below the size of the buffer (4096 bytes) used to read the uploaded file. This caused the file upload process to take several orders of magnitude longer than if the boundary was the typical tens of bytes long. This was fixed in revision 1743722 for 8.5.x and revision 1743738 for 8.0.x. This issue was identified by the TERASOLUNA Framework Development Team and reported to the Apache Commons team via JPCERT on 9 May 2016. It was made public on 21 June 2016. Affects: 8.5.0 to 8.5.2, 8.0.0.R
GHSA
Improper Input Validation in Jenkins
ghsa·2022-05-14·CVSS 7.5
CVE-2017-1000394 [HIGH] CWE-20 Improper Input Validation in Jenkins
Improper Input Validation in Jenkins
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.
OSV
Improper Input Validation in Jenkins
osv·2022-05-14·CVSS 7.5
CVE-2017-1000394 [HIGH] Improper Input Validation in Jenkins
Improper Input Validation in Jenkins
Jenkins 2.73.1 and earlier, 2.83 and earlier bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092. The fix for that vulnerability has been backported to the version of the library bundled with Jenkins.
OSV
High severity vulnerability that affects commons-fileupload:commons-fileupload
osv·2018-12-21
CVE-2016-3092 [HIGH] High severity vulnerability that affects commons-fileupload:commons-fileupload
High severity vulnerability that affects commons-fileupload:commons-fileupload
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
GHSA
High severity vulnerability that affects commons-fileupload:commons-fileupload
ghsa·2018-12-21
CVE-2016-3092 [HIGH] CWE-20 High severity vulnerability that affects commons-fileupload:commons-fileupload
High severity vulnerability that affects commons-fileupload:commons-fileupload
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
OSV
tomcat6, tomcat7 vulnerabilities
osv·2016-07-05·CVSS 4.3
CVE-2015-5174 [MEDIUM] tomcat6, tomcat7 vulnerabilities
tomcat6, tomcat7 vulnerabilities
It was discovered that Tomcat incorrectly handled pathnames used by web
applications in a getResource, getResourceAsStream, or getResourcePaths
call. A remote attacker could use this issue to possibly list a parent
directory . This issue only affected Ubuntu 12.04 LTS, Ubuntu 14.04 LTS and
Ubuntu 15.10. (CVE-2015-5174)
It was discovered that the Tomcat mapper component incorrectly handled
redirects. A remote attacker could use this issue to determine the
existence of a directory. This issue only affected Ubuntu 12.04 LTS,
Ubuntu 14.04 LTS and Ubuntu 15.10. (CVE-2015-5345)
It was discovered that Tomcat incorrectly handled different session
settings when multiple versions of the same web application was deployed. A
remote attacker could possibly use this i
OSV
CVE-2016-3092: The MultipartStream class in Apache Commons Fileupload before 1
osv·2016-07-04·CVSS 7.5
CVE-2016-3092 [HIGH] CVE-2016-3092: The MultipartStream class in Apache Commons Fileupload before 1
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-1000394 jenkins: Jenkins core bundled vulnerable version of the commons-fileupload library (SECURITY-490)
bugzilla·2017-10-13·CVSS 7.5
CVE-2017-1000394 [HIGH] CVE-2017-1000394 jenkins: Jenkins core bundled vulnerable version of the commons-fileupload library (SECURITY-490)
CVE-2017-1000394 jenkins: Jenkins core bundled vulnerable version of the commons-fileupload library (SECURITY-490)
Jenkins bundled a version of the commons-fileupload library with the denial-of-service vulnerability known as CVE-2016-3092.
External References:
https://jenkins.io/security/advisory/2017-10-11/
Discussion:
Created jenkins tracking bugs for this issue:
Affects: openshift-1 [bug 1501968]
---
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1515068]
---
openshift3/jenkins-2-rhel7 now uses version 2.89.2
Marking Openshift Enteprise 3 as not affected.
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2017-1000394
Bugzilla
CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 CVE-2016-3092 tomcat: multiple security vulnerabilities [epel-6]
bugzilla·2016-07-01·CVSS 5.3
CVE-2015-5351 [MEDIUM] CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 CVE-2016-3092 tomcat: multiple security vulnerabilities [epel-6]
CVE-2015-5351 CVE-2016-0714 CVE-2016-0706 CVE-2015-5345 CVE-2015-5346 CVE-2016-0763 CVE-2016-3092 tomcat: multiple security vulnerabilities [epel-6]
+++ This bug was initially created as a clone of Bug #1311102 +++
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also me
Bugzilla
CVE-2016-3092 tomcat: Usage of vulnerable FileUpload package can result in denial of service [fedora-all]
bugzilla·2016-06-23·CVSS 7.5
CVE-2016-3092 [HIGH] CVE-2016-3092 tomcat: Usage of vulnerable FileUpload package can result in denial of service [fedora-all]
CVE-2016-3092 tomcat: Usage of vulnerable FileUpload package can result in denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
Bugzilla
CVE-2016-3092 tomcat: Usage of vulnerable FileUpload package can result in denial of service
bugzilla·2016-06-23·CVSS 7.5
CVE-2016-3092 [HIGH] CVE-2016-3092 tomcat: Usage of vulnerable FileUpload package can result in denial of service
CVE-2016-3092 tomcat: Usage of vulnerable FileUpload package can result in denial of service
Apache Tomcat uses a package renamed copy of Apache Commons FileUpload to implement the file upload requirements of the Servlet specification. A denial of service vulnerability was identified in Commons FileUpload that occurred when the length of the multipart boundary was just below the size of the buffer (4096 bytes) used to read the uploaded file. This caused the file upload process to take several orders of magnitude longer than if the boundary was the typical tens of bytes long.
External references:
http://tomcat.apache.org/security-8.html
http://tomcat.apache.org/security-7.html
Upstream fixes:
Tomcat 8.5.x:
http://svn.apache.org/viewvc?view=revision&revision=1743722
Tomcat 8.0.x:
htt
Bugzilla
CVE-2016-3092 tomcat: Usage of vulnerable FileUpload package can result in denial of service [epel-6]
bugzilla·2016-06-23·CVSS 7.5
CVE-2016-3092 [HIGH] CVE-2016-3092 tomcat: Usage of vulnerable FileUpload package can result in denial of service [epel-6]
CVE-2016-3092 tomcat: Usage of vulnerable FileUpload package can result in denial of service [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
[bug automatically created
arXiv
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
arxiv_fulltext·2018-07-12
Beyond Metadata: Code-centric and Usage-based Analysis of Known Vulnerabilities in Open-source Software
## Abstract
The use of open-source software (OSS) is ever-increasing, and so is the number of open-source vulnerabilities being discovered and publicly disclosed. The gains obtained from the reuse of community-developed libraries may be offset by the cost of timely detecting, assessing, and mitigating their vulnerabilities.
In this paper we present a novel method to detect, assess and mitigate OSS vulnerabilities that improves on state-of-the-art approaches, which commonly depend on metadata to identify vulnerable OSS dependencies. Our solution instead is code-centric and combines static and dynamic analysis to determine the reachability of the vulnerable portion of libraries used (directly or transitively) by an application. Taking this usage into account, our approach then supports dev
http://jvn.jp/en/jp/JVN89379547/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2016-000121http://lists.opensuse.org/opensuse-updates/2016-09/msg00025.htmlhttp://mail-archives.apache.org/mod_mbox/commons-dev/201606.mbox/%3CCAF8HOZ%2BPq2QH8RnxBuJyoK1dOz6jrTiQypAC%2BH8g6oZkBg%2BCxg%40mail.gmail.com%3Ehttp://rhn.redhat.com/errata/RHSA-2016-2068.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2069.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2070.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2071.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2072.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2599.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2807.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2808.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0457.htmlhttp://svn.apache.org/viewvc?view=revision&revision=1743480http://svn.apache.org/viewvc?view=revision&revision=1743722http://svn.apache.org/viewvc?view=revision&revision=1743738http://svn.apache.org/viewvc?view=revision&revision=1743742http://tomcat.apache.org/security-7.htmlhttp://tomcat.apache.org/security-8.htmlhttp://tomcat.apache.org/security-9.htmlhttp://www.debian.org/security/2016/dsa-3609http://www.debian.org/security/2016/dsa-3611http://www.debian.org/security/2016/dsa-3614http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/91453http://www.securitytracker.com/id/1036427http://www.securitytracker.com/id/1036900http://www.securitytracker.com/id/1037029http://www.securitytracker.com/id/1039606http://www.ubuntu.com/usn/USN-3024-1http://www.ubuntu.com/usn/USN-3027-1https://access.redhat.com/errata/RHSA-2017:0455https://access.redhat.com/errata/RHSA-2017:0456https://bugzilla.redhat.com/show_bug.cgi?id=1349468https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05204371https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289840https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324759https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3Ehttps://security.gentoo.org/glsa/201705-09https://security.gentoo.org/glsa/202107-39https://security.netapp.com/advisory/ntap-20190212-0001/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.htmlhttp://jvn.jp/en/jp/JVN89379547/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2016-000121http://lists.opensuse.org/opensuse-updates/2016-09/msg00025.htmlhttp://mail-archives.apache.org/mod_mbox/commons-dev/201606.mbox/%3CCAF8HOZ%2BPq2QH8RnxBuJyoK1dOz6jrTiQypAC%2BH8g6oZkBg%2BCxg%40mail.gmail.com%3Ehttp://rhn.redhat.com/errata/RHSA-2016-2068.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2069.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2070.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2071.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2072.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2599.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2807.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2808.htmlhttp://rhn.redhat.com/errata/RHSA-2017-0457.htmlhttp://svn.apache.org/viewvc?view=revision&revision=1743480http://svn.apache.org/viewvc?view=revision&revision=1743722http://svn.apache.org/viewvc?view=revision&revision=1743738http://svn.apache.org/viewvc?view=revision&revision=1743742http://tomcat.apache.org/security-7.htmlhttp://tomcat.apache.org/security-8.htmlhttp://tomcat.apache.org/security-9.htmlhttp://www.debian.org/security/2016/dsa-3609http://www.debian.org/security/2016/dsa-3611http://www.debian.org/security/2016/dsa-3614http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/91453http://www.securitytracker.com/id/1036427http://www.securitytracker.com/id/1036900http://www.securitytracker.com/id/1037029http://www.securitytracker.com/id/1039606http://www.ubuntu.com/usn/USN-3024-1http://www.ubuntu.com/usn/USN-3027-1https://access.redhat.com/errata/RHSA-2017:0455https://access.redhat.com/errata/RHSA-2017:0456https://bugzilla.redhat.com/show_bug.cgi?id=1349468https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05204371https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05289840https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324759https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/388a323769f1dff84c9ec905455aa73fbcb20338e3c7eb131457f708%40%3Cdev.tomcat.apache.org%3Ehttps://lists.apache.org/thread.html/r9136ff5b13e4f1941360b5a309efee2c114a14855578c3a2cbe5d19c%40%3Cdev.tomcat.apache.org%3Ehttps://security.gentoo.org/glsa/201705-09https://security.gentoo.org/glsa/202107-39https://security.netapp.com/advisory/ntap-20190212-0001/https://www.oracle.com/security-alerts/cpuapr2020.htmlhttps://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
2016-07-04
Published