{"id":"MGASA-2016-0260","summary":"Updated tomcat/apache-commons-fileupload packages fix security vulnerability","details":"The TERASOLUNA Framework Development Team discovered a denial of service\nvulnerability in Apache Commons FileUpload. A remote attacker can take\nadvantage of this flaw by sending file upload requests that cause the HTTP\nserver using the Apache Commons Fileupload library to become unresponsive,\npreventing the server from servicing other requests.\n\nTomcat contains a bundled copy of this library, so it has also been\npatched to fix this issue.\n","modified":"2026-04-16T01:48:07.054292322Z","published":"2016-07-26T21:16:28Z","upstream":["CVE-2016-3092"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0260.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=18803"},{"type":"WEB","url":"http://tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.70"},{"type":"WEB","url":"https://www.debian.org/security/2016/dsa-3611"},{"type":"WEB","url":"https://www.debian.org/security/2016/dsa-3614"}],"affected":[{"package":{"name":"tomcat","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/tomcat?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.0.68-1.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0260.json"}},{"package":{"name":"apache-commons-fileupload","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/apache-commons-fileupload?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.1-4.1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0260.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}