The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-528-1 | libcommons-fileupload-java security update |
Debian DLA |
DLA-529-1 | tomcat7 security update |
Debian DSA |
DSA-3609-1 | tomcat8 security update |
Debian DSA |
DSA-3611-1 | libcommons-fileupload-java security update |
Debian DSA |
DSA-3614-1 | tomcat7 security update |
Github GHSA |
GHSA-fvm3-cfvj-gxqq | High severity vulnerability that affects commons-fileupload:commons-fileupload |
Ubuntu USN |
USN-3024-1 | Tomcat vulnerabilities |
Ubuntu USN |
USN-3027-1 | Tomcat vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T23:40:15.604Z
Reserved: 2016-03-10T00:00:00
Link: CVE-2016-3092
No data.
Status : Deferred
Published: 2016-07-04T22:59:04.303
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-3092
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Github GHSA
Ubuntu USN