MDVSA-2014:095 -- Mandriva strutsID: oval:org.secpod.oval:def:1300305 | Date: (C)2014-06-11 (M)2023-12-07 |
Class: PATCH | Family: unix |
Updated struts packages fix security vulnerability: It was found that the Struts 1 ActionForm object allowed access to the 'class' parameter, which is directly mapped to the getClass method. A remote attacker could use this flaw to manipulate the ClassLoader used by an application server running Struts 1. This could lead to remote code execution under certain conditions .
Platform: |
Mandriva Enterprise Server 5.2 |