CVE-2011-2729
Summary
| CVE | CVE-2011-2729 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-08-15 21:55:02 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | native/unix/native/jsvc-unix.c in jsvc in the Daemon component 1.0.3 through 1.0.6 in Apache Commons, as used in Apache Tomcat 5.5.32 through 5.5.33, 6.0.30 through 6.0.32, and 7.0.x before 7.0.20 on Linux, does not drop capabilities, which allows remote attackers to bypass read permissions for files via a request to an application. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Apache Commons Daemon | 1.0.3 | All | All | All |
| Application | Apache | Apache Commons Daemon | 1.0.4 | All | All | All |
| Application | Apache | Apache Commons Daemon | 1.0.5 | All | All | All |
| Application | Apache | Apache Commons Daemon | 1.0.6 | All | All | All |
| Application | Apache | Tomcat | 5.5.32 | All | All | All |
| Application | Apache | Tomcat | 5.5.33 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Apache Tomcat Commons Daemon jsvc Lets Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| [AANNOUNCE] Apache Commons Daemon 1.0.7 released | af854a3a-2127-422b-91ae-364da2661108 | mail-archives.apache.org | |
| [Apache-SVN] Revision 1153824 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| '[security bulletin] HPSBUX02860 SSRT101146 rev.1 - HP-UX Apache Running Tomcat Servlet Engine, Remot' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Apache Tomcat® - Apache Tomcat 7 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Vendor Advisory |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| Support | af854a3a-2127-422b-91ae-364da2661108 | www.redhat.com | |
| [SECURITY] CVE-2011-2729: Commons Daemon fails to drop capabilities (Apache Tomcat) | af854a3a-2127-422b-91ae-364da2661108 | mail-archives.apache.org | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| [security-announce] openSUSE-SU-2011:1062-1: important: jakarta-commons- | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| '[security bulletin] HPSBUX02725 SSRT100627 rev.1 - HP-UX Apache Running Tomcat Servlet Engine, Remot' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| Bug 730400 – CVE-2011-2729 jakarta-commons-daemon: jsvc does not drop capabilities allowing access to files and directories owned by the superuser | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| Apache Tomcat - Apache Tomcat 5 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Vendor Advisory |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | people.apache.org | |
| Apache Tomcat® - Apache Tomcat 6 vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | tomcat.apache.org | Vendor Advisory |
| Red Hat update for JBoss Enterprise Web Server - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| [Apache-SVN] Revision 1153379 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| '[security bulletin] HPSBOV02762 SSRT100825 rev.1 - HP Secure Web Server (SWS) for OpenVMS running CS' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| '[security bulletin] HPSBST02955 rev.1 - HP XP P9000 Performance Advisor Software, 3rd party Software' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| [Apache-SVN] Revision 1152701 | af854a3a-2127-422b-91ae-364da2661108 | svn.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| [DAEMON-214] CVE-2011-2729: jsvc fails to drop capabilities on Linux - ASF JIRA | af854a3a-2127-422b-91ae-364da2661108 | issues.apache.org | |
| Pony Mail! | af854a3a-2127-422b-91ae-364da2661108 | lists.apache.org | |
| [AANNOUNCE] Apache Commons Daemon 1.0.7 released | MITRE | mail-archives.apache.org | |
| [SECURITY] CVE-2011-2729: Commons Daemon fails to drop capabilities (Apache Tomcat) | MITRE | mail-archives.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| Pony Mail! | MITRE | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.