Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
BID:49143
Info
Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
| Bugtraq ID: | 49143 |
| Class: | Access Validation Error |
| CVE: |
CVE-2011-2729 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2011 12:00AM |
| Updated: | Mar 19 2015 08:29AM |
| Credit: | Wilfried Weissmann |
| Vulnerable: |
Ubuntu Ubuntu Linux 11.10 i386 Ubuntu Ubuntu Linux 11.10 amd64 Ubuntu Ubuntu Linux 11.04 powerpc Ubuntu Ubuntu Linux 11.04 i386 Ubuntu Ubuntu Linux 11.04 ARM Ubuntu Ubuntu Linux 11.04 amd64 Sun Solaris 10 S.u.S.E. openSUSE 11.4 Redhat JBoss Enterprise Web Server for RHEL 4 ES 1.0 Redhat JBoss Enterprise Web Server for RHEL 4 AS 1.0 IBM Rational Policy Tester 8.5.0.1 IBM Rational Policy Tester 8.5 IBM Rational Policy Tester 8.0 IBM Rational AppScan Enterprise 8.6 IBM Rational AppScan Enterprise 8.5.0.1 IBM Rational AppScan Enterprise 8.0.1.1 IBM Rational AppScan Enterprise 8.0.1 IBM Rational AppScan Enterprise 8.0.0.1 IBM Rational AppScan Enterprise 8.0.0 HP XP P9000 Performance Advisor 5.4.1 HP OpenVMS Secure Web Server 7.3 -2 HP OpenVMS Secure Web Server 7.3 -1 HP OpenVMS Secure Web Server 7.3 HP OpenVMS Secure Web Server 7.2 -2 HP OpenVMS Secure Web Server 1.2 HP OpenVMS Secure Web Server 1.1 -1 HP OpenVMS Secure Web Server 2.2 HP OpenVMS Secure Web Server 2.1-1 HP HP-UX Web Server Suite 3.22 HP HP-UX Web Server Suite 3.21 HP HP-UX Web Server Suite 3.18 HP HP-UX Web Server Suite 3.17 HP HP-UX B.11.31 HP HP-UX B.11.31 HP HP-UX B.11.23 Gentoo Linux CTERA Networks CTERA Portal 3.1 Blue Coat Systems Intelligence Center 3.2.1 Blue Coat Systems Intelligence Center 3.1.2 Blue Coat Systems Intelligence Center 3.1.1 Blue Coat Systems Intelligence Center 2.1.2 Blue Coat Systems Intelligence Center 2.1.1 Blue Coat Systems Intelligence Center 2.1 Blue Coat Systems Intelligence Center 2.0.1 Blue Coat Systems Intelligence Center 2.0 Blue Coat Systems Intelligence Center 3.2 Blue Coat Systems Intelligence Center 3.1 Avaya Aura Experience Portal 6.0 Avaya Aura Application Enablement Services 6.1.1 Avaya Aura Application Enablement Services 6.1 Apache Tomcat 7.0.15 Apache Tomcat 7.0.14 Apache Tomcat 7.0.13 Apache Tomcat 7.0.12 Apache Tomcat 7.0.9 Apache Tomcat 7.0.8 Apache Tomcat 7.0.7 Apache Tomcat 7.0.6 Apache Tomcat 7.0.4 Apache Tomcat 7.0.3 Apache Tomcat 7.0.2 Apache Tomcat 7.0.1 Apache Tomcat 7.0 beta Apache Tomcat 7.0 Apache Tomcat 5.5.32 Apache Tomcat 7.0.5 Apache Tomcat 7.0.19 Apache Tomcat 7.0.18 Apache Tomcat 7.0.17 Apache Tomcat 7.0.11 Apache Tomcat 7.0.10 Apache Tomcat 7.0 Apache Tomcat 6.0.32 Apache Tomcat 6.0.31 Apache Tomcat 6.0.30 Apache Tomcat 5.5.33 Apache Tomcat 5.5.33 Apache Geronimo 2.1.7 Apache Geronimo 2.1.6 Apache Geronimo 2.1.5 Apache Geronimo 2.1.4 Apache Geronimo 2.1.3 Apache Geronimo 2.1.2 Apache Geronimo 2.1.1 Apache Geronimo 2.0.2 Apache Geronimo 2.0.1 Apache Geronimo 1.1.1 Apache Geronimo 1.1 Apache Geronimo 1.0.1 Apache Geronimo 1.0 Apache Geronimo 2.1 Apache Geronimo 2.0 Apache Geronimo 1.2 Apache Geronimo 1.1 Apache Geronimo 1.0 Apache Commons Daemon 1.0.6 |
| Not Vulnerable: |
HP XP P9000 Performance Advisor 5.5.1 CTERA Networks CTERA Portal 3.2.28 CTERA Networks CTERA Portal 3.1.39 Blue Coat Systems Intelligence Center 3.2.2.1 Apache Tomcat 5.5.34 Apache Tomcat 7.0.20 Apache Tomcat 6.0.33 Apache Geronimo 2.1.8 Apache Commons Daemon 1.0.7 |
Discussion
Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
Apache Commons Daemon is prone to a remote information-disclosure vulnerability that affects the 'jsvc' library.
Remote attackers can exploit this issue to gain access to files and directories owned by the superuser, through applications using the affected library. This allows attackers to obtain sensitive information that may aid in further attacks.
Note: This issue affects applications running on Linux operating systems only.
Versions prior to Commons Daemon 1.0.7 are vulnerable.
The following Apache Tomcat versions which use the affected library are vulnerable:
Tomcat 7.0.0 through 7.0.19
Tomcat 6.0.30 through 6.0.32
Tomcat 5.5.32 through 5.5.33
Apache Commons Daemon is prone to a remote information-disclosure vulnerability that affects the 'jsvc' library.
Remote attackers can exploit this issue to gain access to files and directories owned by the superuser, through applications using the affected library. This allows attackers to obtain sensitive information that may aid in further attacks.
Note: This issue affects applications running on Linux operating systems only.
Versions prior to Commons Daemon 1.0.7 are vulnerable.
The following Apache Tomcat versions which use the affected library are vulnerable:
Tomcat 7.0.0 through 7.0.19
Tomcat 6.0.30 through 6.0.32
Tomcat 5.5.32 through 5.5.33
Exploit / POC
Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
Apache Commons Daemon 'jsvc' Information Disclosure Vulnerability
References:
References:
- [SECURITY] CVE-2011-2729: Commons Daemon fails to drop capabilities (Apache Tomc (Apache Software Foundation)
- Apache Commons Daemon (Apache Software Foundation)
- Apache Tomcat 5.x vulnerabilities (Apache)
- Apache Tomcat 6.x vulnerabilities (Apache)
- Apache Tomcat 7.x vulnerabilities (Apache Software Foundation)
- Apache Tomcat Homepage (Apache)
- Fixed in Geronimo 2.1.8 (Apache Geronimo)
- HPSBUX02725 SSRT100627 rev.1 - HP-UX Apache Running Tomcat Servlet Engine, Remot (HP)
- Jsvc Homepage (Apache Software Foundation)
- Multiple vulnerabilities in CTERA Portal (SEC Consult Vulnerability Lab)
- Multiple vulnerabilities in Oracle Java Web Console (Oracle)
- Multiple vulnerabilities in Oracle Java Web Console1 (Oracle)
- ASA-2011-331 Apache Tomcat Commons Daemon fails to drop capabilities (CVE-2011-2 (Avaya)
- HPSBST02955 rev.1 - HP XP P9000 Performance Advisor Software, 3rd party Software (HP)
- HPSBUX02860 SSRT101146 rev.1 - HP-UX Apache Running Tomcat Servlet Engine, Remot (HP)
- January 10, 2012 - Multiple Tomcat vulnerabilities in IntelligenceCenter (Blue Coat Systems)
- Security Bulletin: Vulnerabilities in AppScan Enterprise and Policy Tester (IBM)