The Commons FileUpload package makes it easy to add robust, high-performance,
file upload capability to your servlets and web applications.
FileUpload parses HTTP requests which conform to RFC 1867, "Form-based File
Upload in HTML". That is, if an HTTP request is submitted using the POST
method, and with a content type of "multipart/form-data", then FileUpload
can parse that request, and make the results available in a manner easily
used by the caller.


2016-06-22 - Emmanuel Bourg <>
libcommons-fileupload-java (1.3.1-1+deb8u1) jessie-security; urgency=high
* Fixed CVE-2016-3092: Denial-of-Service vulnerability
2014-02-06 - Emmanuel Bourg <>
libcommons-fileupload-java (1.3.1-1) unstable; urgency=medium
* New upstream release
- Addresses security issue: CVE-2014-0050
* Removed 002_CVE-2013-2186.patch (applied upstream)
2013-12-03 - Emmanuel Bourg <>
libcommons-fileupload-java (1.3-3) unstable; urgency=low
* Set the property to fix a test failure
(Closes: #730970)
* Removed the Servlet and the Portlet APIs from the runtime dependencies
since they are provided by the Servlet container.
* Install the upstream changelog
* debian/control:
- Standards-Version updated to 3.9.5 (no changes)
- Use canonical URLs for the Vcs-* fields
* Switch to debhelper level 9
2013-11-15 - Salvatore Bonaccorso <>
libcommons-fileupload-java (1.3-2.1) unstable; urgency=low
* Non-maintainer upload.
* Add CVE-2013-2186.patch patch.
CVE-2013-2186: Arbitrary file upload via deserialization. Properly validate
repository in org.apache.commons.fileupload.disk.DiskFileItem.
Thanks to Marc Deslauriers <> for
providing the debdiff. (Closes: #726601)
2013-05-23 - tony mancill <>
libcommons-fileupload-java (1.3-2) unstable; urgency=low
* Team upload.
* Upload to unstable.
2013-04-23 - Emmanuel Bourg <>
libcommons-fileupload-java (1.3-1) experimental; urgency=low
* Team upload
* New upstream release.
* Upgraded the dependency on the Servlet API (2.5 -> 3.0)
* Enabled the unit tests
* Removed Michael Koch from the uploaders list (Closes: #654055)
* Bump Standards-Version to 3.9.4 (no changes)
* Machine-readable debian/copyright file (DEP5)
2010-08-04 - Damien Raude-Morvan <>
libcommons-fileupload-java (1.2.2-1) unstable; urgency=low
* New upstream release.
* New libcommons-fileupload-java-doc package for Javadoc.
* Bump Standards-Version to 3.9.1:
- Add recommended get-orig-source target in d/rules.
* d/dirs: Remove, uneeded.
* Switch to maven-debian-helper for build:
- Drop all patches on old Ant build.
- Add maven-debian-helper to B-D.
- Drop ant from B-D.
* Don't Depends on a JRE (not requested anymore by Java Policy for
libraries packages).
2010-06-11 - Thierry Carrez <>
libcommons-fileupload-java (1.2.1-5) unstable; urgency=low
* (Build-)Depend on libservlet2.5-java instead of libservlet2.4-java
2010-04-12 - Damien Raude-Morvan <>
libcommons-fileupload-java (1.2.1-4) unstable; urgency=low
[ Thierry Carrez ]
* Minimal dependency on default-jre-headless | java2-runtime-headless
* debian/ Force Java2 code to match dependency
[ Damien Raude-Morvan ]
* Remove Arnaud from Uploaders.
* Add myself to Uploaders.
* Bump Standards-Version to 3.8.4: no changes needed
* Bump debhelper to >= 7
* Remove version criteria from cdbs B-D (even stable match version)
* Enable portlet support:
- Remove debian/patches/04_disable-portlet.patch
- Add B-D-I on libportlet-api-2.0-spec-java
- Remove debian/README.Debian
(Closes: #577474)
* Convert to source format 3.0 (quilt)
- Refresh all patches
- Add DEP3 headers to patches
* Register in maven repository:
- B-D-I on maven-repo-helper
- Use mh_installpoms and mh_installjar
2009-09-16 - Michael Koch <>
libcommons-fileupload-java (1.2.1-3) unstable; urgency=low
* (Build-)Depends on default-jdk.
* (Build-)Depends on libservlet2.4-java.

