---
id: CVE-2014-0050
title: >-
  MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in
  Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause
  a denial of service (infinite loop and CPU consumption) via a crafted
  Content-Type …
summary: >-
  MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in
  Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause
  a denial of service (infinite loop and CPU consumption) via a crafted
  Content-Type …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-264
  - CWE-835
vendor: oracle
product: retail_applications
affected:
  - retail_applications = 12.0
  - retail_applications = 12.0in
  - retail_applications = 13.0
  - retail_applications = 13.1
  - retail_applications = 13.2
  - retail_applications = 13.3
  - retail_applications = 13.4
  - retail_applications = 14.0
  - commons_fileupload <= 1.3
  - commons_fileupload = 1.0
  - commons_fileupload = 1.1
  - commons_fileupload = 1.1.1
  - commons_fileupload = 1.2
  - commons_fileupload = 1.2.1
  - commons_fileupload = 1.2.2
  - tomcat = 7.0.0
  - tomcat = 7.0.1
  - tomcat = 7.0.2
  - tomcat = 7.0.3
  - tomcat = 7.0.4
  - tomcat = 7.0.5
  - tomcat = 7.0.6
  - tomcat = 7.0.7
  - tomcat = 7.0.8
  - tomcat = 7.0.9
  - tomcat = 7.0.10
  - tomcat = 7.0.11
  - tomcat = 7.0.12
  - tomcat = 7.0.13
  - tomcat = 7.0.14
  - tomcat = 7.0.15
  - tomcat = 7.0.16
  - tomcat = 7.0.17
  - tomcat = 7.0.18
  - tomcat = 7.0.19
  - tomcat = 7.0.20
  - tomcat = 7.0.21
  - tomcat = 7.0.22
  - tomcat = 7.0.23
  - tomcat = 7.0.24
  - tomcat = 7.0.25
  - tomcat = 7.0.26
  - tomcat = 7.0.27
  - tomcat = 7.0.28
  - tomcat = 7.0.29
  - tomcat = 7.0.30
  - tomcat = 7.0.31
  - tomcat = 7.0.32
  - tomcat = 7.0.33
  - tomcat = 7.0.34
  - tomcat = 7.0.35
  - tomcat = 7.0.36
  - tomcat = 7.0.37
  - tomcat = 7.0.38
  - tomcat = 7.0.39
  - tomcat = 7.0.40
  - tomcat = 7.0.41
  - tomcat = 7.0.42
  - tomcat = 7.0.43
  - tomcat = 7.0.44
  - tomcat = 7.0.45
  - tomcat = 7.0.46
  - tomcat = 7.0.47
  - tomcat = 7.0.48
  - tomcat = 7.0.49
  - tomcat = 7.0.50
  - tomcat = 8.0.0
  - tomcat = 8.0.1
published: '2014-04-01'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:05.247'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2014-0050'
references:
  - url: 'http://advisories.mageia.org/MGASA-2014-0110.html'
    label: secalert@redhat.com
  - url: >-
      http://blog.spiderlabs.com/2014/02/cve-2014-0050-exploit-with-boundaries-loops-without-boundaries.html
    label: secalert@redhat.com
  - url: 'http://jvn.jp/en/jp/JVN14876762/index.html'
    label: secalert@redhat.com
  - url: 'http://jvndb.jvn.jp/jvndb/JVNDB-2014-000017'
    label: secalert@redhat.com
  - url: >-
      http://mail-archives.apache.org/mod_mbox/commons-dev/201402.mbox/%3C52F373FC.9030907%40apache.org%3E
    label: secalert@redhat.com
  - url: 'http://marc.info/?l=bugtraq&m=143136844732487&w=2'
    label: secalert@redhat.com
  - url: >-
      http://packetstormsecurity.com/files/127215/VMware-Security-Advisory-2014-0007.html
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2014-0252.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2014-0253.html'
    label: secalert@redhat.com
  - url: 'http://rhn.redhat.com/errata/RHSA-2014-0400.html'
    label: secalert@redhat.com
  - url: 'http://seclists.org/fulldisclosure/2014/Dec/23'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/57915'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/58075'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/58976'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/59039'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/59041'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/59183'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/59184'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/59185'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/59187'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/59232'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/59399'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/59492'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/59500'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/59725'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/60475'
    label: secalert@redhat.com
  - url: 'http://secunia.com/advisories/60753'
    label: secalert@redhat.com
  - url: 'http://svn.apache.org/r1565143'
    label: secalert@redhat.com
  - url: 'http://tomcat.apache.org/security-7.html'
    label: secalert@redhat.com
  - url: 'http://tomcat.apache.org/security-8.html'
    label: secalert@redhat.com
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21669554'
    label: secalert@redhat.com
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21675432'
    label: secalert@redhat.com
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676091'
    label: secalert@redhat.com
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676092'
    label: secalert@redhat.com
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676401'
    label: secalert@redhat.com
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676403'
    label: secalert@redhat.com
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676405'
    label: secalert@redhat.com
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676410'
    label: secalert@redhat.com
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676656'
    label: secalert@redhat.com
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676853'
    label: secalert@redhat.com
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21677691'
    label: secalert@redhat.com
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21677724'
    label: secalert@redhat.com
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21681214'
    label: secalert@redhat.com
  - url: 'http://www.debian.org/security/2014/dsa-2856'
    label: secalert@redhat.com
  - url: >-
      http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-015/index.html
    label: secalert@redhat.com
  - url: >-
      http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-016/index.html
    label: secalert@redhat.com
  - url: >-
      http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-017/index.html
    label: secalert@redhat.com
  - url: >-
      http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-350733.htm
    label: secalert@redhat.com
  - url: 'http://www.mandriva.com/security/advisories?name=MDVSA-2015:084'
    label: secalert@redhat.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
    label: secalert@redhat.com
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
    label: secalert@redhat.com
  - url: 'http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html'
    label: secalert@redhat.com
  - url: 'http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html'
    label: secalert@redhat.com
  - url: 'http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html'
    label: secalert@redhat.com
  - url: 'http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html'
    label: secalert@redhat.com
  - url: 'http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html'
    label: secalert@redhat.com
  - url: 'http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html'
    label: secalert@redhat.com
  - url: 'http://www.securityfocus.com/archive/1/532549/100/0/threaded'
    label: secalert@redhat.com
  - url: 'http://www.securityfocus.com/archive/1/534161/100/0/threaded'
    label: secalert@redhat.com
  - url: 'http://www.securityfocus.com/bid/65400'
    label: secalert@redhat.com
  - url: 'http://www.ubuntu.com/usn/USN-2130-1'
    label: secalert@redhat.com
  - url: 'http://www.vmware.com/security/advisories/VMSA-2014-0007.html'
    label: secalert@redhat.com
  - url: 'http://www.vmware.com/security/advisories/VMSA-2014-0008.html'
    label: secalert@redhat.com
  - url: 'http://www.vmware.com/security/advisories/VMSA-2014-0012.html'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1062337'
    label: secalert@redhat.com
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755
    label: secalert@redhat.com
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917
    label: secalert@redhat.com
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
    label: secalert@redhat.com
  - url: 'https://security.gentoo.org/glsa/202107-39'
    label: secalert@redhat.com
  - url: 'http://advisories.mageia.org/MGASA-2014-0110.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://blog.spiderlabs.com/2014/02/cve-2014-0050-exploit-with-boundaries-loops-without-boundaries.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://jvn.jp/en/jp/JVN14876762/index.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://jvndb.jvn.jp/jvndb/JVNDB-2014-000017'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://mail-archives.apache.org/mod_mbox/commons-dev/201402.mbox/%3C52F373FC.9030907%40apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://marc.info/?l=bugtraq&m=143136844732487&w=2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://packetstormsecurity.com/files/127215/VMware-Security-Advisory-2014-0007.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2014-0252.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2014-0253.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://rhn.redhat.com/errata/RHSA-2014-0400.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2014/Dec/23'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/57915'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/58075'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/58976'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/59039'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/59041'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/59183'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/59184'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/59185'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/59187'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/59232'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/59399'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/59492'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/59500'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/59725'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/60475'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://secunia.com/advisories/60753'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://svn.apache.org/r1565143'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-7.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tomcat.apache.org/security-8.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21669554'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21675432'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676091'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676092'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676401'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676403'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676405'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676410'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676656'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21676853'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21677691'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21677724'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www-01.ibm.com/support/docview.wss?uid=swg21681214'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.debian.org/security/2014/dsa-2856'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-015/index.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-016/index.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.hitachi.co.jp/Prod/comp/soft1/global/security/info/vuls/HS14-017/index.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.huawei.com/en/security/psirt/security-bulletins/security-advisories/hw-350733.htm
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.mandriva.com/security/advisories?name=MDVSA-2015:084'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.oracle.com/technetwork/topics/security/cpujul2014-1972956.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/archive/1/532549/100/0/threaded'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/archive/1/534161/100/0/threaded'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/65400'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.ubuntu.com/usn/USN-2130-1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.vmware.com/security/advisories/VMSA-2014-0007.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.vmware.com/security/advisories/VMSA-2014-0008.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.vmware.com/security/advisories/VMSA-2014-0012.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1062337'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05324755
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05376917
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05390722
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202107-39'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-10-07T17:56:23.942074Z'
epss: 0.83175
epssPercentile: 0.99672
exploits:
  exploitdb: true
  github: 1
  githubRepos:
    - 'https://github.com/jrrdev/cve-2014-0050'
  metasploit:
    - auxiliary/dos/http/apache_commons_fileupload_dos
  checkedAt: '2026-10-07T18:42:55.473Z'
exploitAvailable: true
ingestedAt: '2026-10-07T18:42:20.868Z'
---

## Overview

MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.

## Affected

- `retail_applications = 12.0`
- `retail_applications = 12.0in`
- `retail_applications = 13.0`
- `retail_applications = 13.1`
- `retail_applications = 13.2`
- `retail_applications = 13.3`
- `retail_applications = 13.4`
- `retail_applications = 14.0`
- `commons_fileupload <= 1.3`
- `commons_fileupload = 1.0`
- `commons_fileupload = 1.1`
- `commons_fileupload = 1.1.1`
- `commons_fileupload = 1.2`
- `commons_fileupload = 1.2.1`
- `commons_fileupload = 1.2.2`
- `tomcat = 7.0.0`
- `tomcat = 7.0.1`
- `tomcat = 7.0.2`
- `tomcat = 7.0.3`
- `tomcat = 7.0.4`
- `tomcat = 7.0.5`
- `tomcat = 7.0.6`
- `tomcat = 7.0.7`
- `tomcat = 7.0.8`
- `tomcat = 7.0.9`
- `tomcat = 7.0.10`
- `tomcat = 7.0.11`
- `tomcat = 7.0.12`
- `tomcat = 7.0.13`
- `tomcat = 7.0.14`
- `tomcat = 7.0.15`
- `tomcat = 7.0.16`
- `tomcat = 7.0.17`
- `tomcat = 7.0.18`
- `tomcat = 7.0.19`
- `tomcat = 7.0.20`
- `tomcat = 7.0.21`
- `tomcat = 7.0.22`
- `tomcat = 7.0.23`
- `tomcat = 7.0.24`
- `tomcat = 7.0.25`
- `tomcat = 7.0.26`
- `tomcat = 7.0.27`
- `tomcat = 7.0.28`
- `tomcat = 7.0.29`
- `tomcat = 7.0.30`
- `tomcat = 7.0.31`
- `tomcat = 7.0.32`
- `tomcat = 7.0.33`
- `tomcat = 7.0.34`
- `tomcat = 7.0.35`
- `tomcat = 7.0.36`
- `tomcat = 7.0.37`
- `tomcat = 7.0.38`
- `tomcat = 7.0.39`
- `tomcat = 7.0.40`
- `tomcat = 7.0.41`
- `tomcat = 7.0.42`
- `tomcat = 7.0.43`
- `tomcat = 7.0.44`
- `tomcat = 7.0.45`
- `tomcat = 7.0.46`
- `tomcat = 7.0.47`
- `tomcat = 7.0.48`
- `tomcat = 7.0.49`
- `tomcat = 7.0.50`
- `tomcat = 8.0.0`
- `tomcat = 8.0.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
