[jira] [Commented] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Mark Thomas (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15666372#comment-15666372 ] Mark Thomas commented on FILEUPLOAD-279: -1 to back-porting since it breaks backwards

[jira] [Updated] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Chris Seieroe updated FILEUPLOAD-279: - Attachment: fix2.patch I reapplied the fixes on a clean copy, and the patch looks a

[jira] [Updated] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Chris Seieroe updated FILEUPLOAD-279: - Attachment: (was:

[jira] [Commented] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15665795#comment-15665795 ] Chris Seieroe commented on FILEUPLOAD-279: -- Looking back at the patch, it's a lot larger than

[jira] [Updated] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Chris Seieroe updated FILEUPLOAD-279: - Attachment: 0001-Fix-CVE-2016-131-by-making-DiskFileItem-not-Seri.patch First

[jira] [Commented] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Gary Gregory (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15665725#comment-15665725 ] Gary Gregory commented on FILEUPLOAD-279: - Patches welcome! > CVE-2016-131 - Apache

[jira] [Comment Edited] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15665692#comment-15665692 ] Chris Seieroe edited comment on FILEUPLOAD-279 at 11/15/16 1:40 AM:

[jira] [Commented] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15665692#comment-15665692 ] Chris Seieroe commented on FILEUPLOAD-279: -- I noticed that in the main branch, back in May,

[jira] [Work logged] (TEXT-23) Move text related code from commons-lang into commons-text

2016-11-14 Thread Rob Tompkins (JIRA)
[ https://issues.apache.org/jira/browse/TEXT-23?focusedWorklogId=32044=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-32044 ] Rob Tompkins logged work on TEXT-23: Author: Rob Tompkins Created on:

[jira] [Work logged] (TEXT-23) Move text related code from commons-lang into commons-text

2016-11-14 Thread Rob Tompkins (JIRA)
[ https://issues.apache.org/jira/browse/TEXT-23?focusedWorklogId=32045=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-32045 ] Rob Tompkins logged work on TEXT-23: Author: Rob Tompkins Created on:

[jira] [Resolved] (TEXT-23) Move text related code from commons-lang into commons-text

2016-11-14 Thread Rob Tompkins (JIRA)
[ https://issues.apache.org/jira/browse/TEXT-23?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Rob Tompkins resolved TEXT-23. -- Resolution: Implemented > Move text related code from commons-lang into commons-text >

[jira] [Commented] (TEXT-23) Move text related code from commons-lang into commons-text

2016-11-14 Thread Rob Tompkins (JIRA)
[ https://issues.apache.org/jira/browse/TEXT-23?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15664913#comment-15664913 ] Rob Tompkins commented on TEXT-23: -- Resolved by: https://github.com/apache/commons-text/pull/8 > Move text

[jira] [Created] (IO-522) Symbolic links get followed in deleteQuietly

2016-11-14 Thread Daniel Temme (JIRA)
Daniel Temme created IO-522: --- Summary: Symbolic links get followed in deleteQuietly Key: IO-522 URL: https://issues.apache.org/jira/browse/IO-522 Project: Commons IO Issue Type: Bug

[jira] [Updated] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Michiel Weggen (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Michiel Weggen updated FILEUPLOAD-279: -- Description: http://www.tenable.com/security/research/tra-2016-12 Summary There

[jira] [Created] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Michiel Weggen (JIRA)
Michiel Weggen created FILEUPLOAD-279: - Summary: CVE-2016-131 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution Key: FILEUPLOAD-279 URL:

[jira] [Commented] (POOL-315) GenericObjectPool close() does not wait for the current eviction task

2016-11-14 Thread Mark Thomas (JIRA)
[ https://issues.apache.org/jira/browse/POOL-315?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15663312#comment-15663312 ] Mark Thomas commented on POOL-315: -- Thanks for the review. Patch applied. > GenericObjectPool close() does

[jira] [Commented] (CRYPTO-129) Change access of instance variables from package private to private (or protected if appropriate)

2016-11-14 Thread Jianguo Tian (JIRA)
[ https://issues.apache.org/jira/browse/CRYPTO-129?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15663091#comment-15663091 ] Jianguo Tian commented on CRYPTO-129: - I have fixed this jira with the first step and I have [pull