Sync libcommons-fileupload-java 1.3-2.1 (universe) from Debian unstable (main)
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
libcommons-fileupload-java (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Please sync libcommons-
Explanation of the Ubuntu delta and why it can be dropped:
* SECURITY UPDATE: arbitrary file overwrite via poison null byte
- debian/
src/
- CVE-2013-2186
Debian has merged Ubuntu changes.
Changelog entries since current trusty version 1.3-2ubuntu1:
libcommons-
* Non-maintainer upload.
* Add CVE-2013-2186.patch patch.
CVE-2013-2186: Arbitrary file upload via deserialization. Properly
validate repository in src/main/
Thanks to Marc Deslauriers <email address hidden> for
providing the debdiff. (Closes: #726601)
-- Salvatore Bonaccorso <email address hidden> Fri, 15 Nov 2013 15:04:17 +0100
This fails to build for me on amd64 trusty:
Running org.apache. commons. fileupload. MultipartStream Test
Tests run: 2, Failures: 0, Errors: 0, Skipped: 0, Time elapsed: 0 sec
Results :
Failed tests: decodeUtf8Base6 4Encoded( org.apache. commons. fileupload. util.mime. MimeUtilityTest Case): expected:< h[?! ???]u !!!> but was:< h[?! ???]u !!!> tedPrintableEnc oded(org. apache. commons. fileupload. util.mime. MimeUtilityTest Case): expected:< h[?! ???]u !!!> but was:< h[?! ???]u !!!>
decodeUtf8Quo
Tests run: 67, Failures: 2, Errors: 0, Skipped: 0
[INFO] ------- ------- ------- ------- ------- ------- ------- ------- ------- ------- -- ------- ------- ------- ------- ------- ------- ------- ------- ------- --
[ERROR] BUILD FAILURE
[INFO] -------
[INFO] There are test failures.
Please refer to /tmp/buildd/ libcommons- fileupload- java-1. 3/target/ surefire- reports for the individual test results. ------- ------- ------- ------- ------- ------- ------- ------- ------- -- ------- ------- ------- ------- ------- ------- ------- ------- ------- -- ------- ------- ------- ------- ------- ------- ------- ------- ------- --
[INFO] -------
[INFO] For more information, run Maven with the -e switch
[INFO] -------
[INFO] Total time: 5 seconds
[INFO] Finished at: Fri Nov 22 06:56:26 UTC 2013
[INFO] Final Memory: 17M/210M
[INFO] -------
make: *** [mvn-build] Error 1