Advisories ยป MGASA-2014-0219

Updated struts packages fix CVE-2014-0114

Publication date: 14 May 2014
Type: security
Affected Mageia releases : 3 , 4
CVE: CVE-2014-0114

Description

Updated struts packages fix security vulnerability:

It was found that the Struts 1 ActionForm object allowed access to the
'class' parameter, which is directly mapped to the getClass() method. A
remote attacker could use this flaw to manipulate the ClassLoader used by
an application server running Struts 1. This could lead to remote code
execution under certain conditions (CVE-2014-0114).
                

References

SRPMS

3/core

4/core