[jira] [Commented] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-29 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15707286#comment-15707286 ] Chris Seieroe commented on FILEUPLOAD-279: -- I understand the larger problem, and that's

[jira] [Commented] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-15 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15667888#comment-15667888 ] Chris Seieroe commented on FILEUPLOAD-279: -- Are you saying it breaks backwards compatibility

[jira] [Updated] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Chris Seieroe updated FILEUPLOAD-279: - Attachment: fix2.patch I reapplied the fixes on a clean copy, and the patch looks a

[jira] [Updated] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Chris Seieroe updated FILEUPLOAD-279: - Attachment: (was:

[jira] [Commented] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15665795#comment-15665795 ] Chris Seieroe commented on FILEUPLOAD-279: -- Looking back at the patch, it's a lot larger than

[jira] [Updated] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Chris Seieroe updated FILEUPLOAD-279: - Attachment: 0001-Fix-CVE-2016-131-by-making-DiskFileItem-not-Seri.patch First

[jira] [Comment Edited] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15665692#comment-15665692 ] Chris Seieroe edited comment on FILEUPLOAD-279 at 11/15/16 1:40 AM:

[jira] [Commented] (FILEUPLOAD-279) CVE-2016-1000031 - Apache Commons FileUpload DiskFileItem File Manipulation Remote Code Execution

2016-11-14 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-279?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15665692#comment-15665692 ] Chris Seieroe commented on FILEUPLOAD-279: -- I noticed that in the main branch, back in May,

[jira] [Created] (CONFIGURATION-533) Can DatabaseConfiguration turn CLOB values into a Strings before returning from getProperty(String)?

2013-03-15 Thread Chris Seieroe (JIRA)
Chris Seieroe created CONFIGURATION-533: --- Summary: Can DatabaseConfiguration turn CLOB values into a Strings before returning from getProperty(String)? Key: CONFIGURATION-533 URL:

[jira] [Commented] (CONFIGURATION-515) Make private methods in PropertiesConfiguration.PropertiesWriter protected

2012-12-05 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/CONFIGURATION-515?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13511050#comment-13511050 ] Chris Seieroe commented on CONFIGURATION-515: - For backwards

[jira] [Created] (CONFIGURATION-515) Make private methods in PropertiesConfiguration.PropertiesWriter protected

2012-11-14 Thread Chris Seieroe (JIRA)
Chris Seieroe created CONFIGURATION-515: --- Summary: Make private methods in PropertiesConfiguration.PropertiesWriter protected Key: CONFIGURATION-515 URL:

[jira] [Commented] (CONFIGURATION-482) Optional dependencies are not marked optional in the manifest's Import-Package section

2012-04-26 Thread Chris Seieroe (JIRA)
[ https://issues.apache.org/jira/browse/CONFIGURATION-482?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanelfocusedCommentId=13262885#comment-13262885 ] Chris Seieroe commented on CONFIGURATION-482: - Perhaps there's a bug