struts-1.2.9-4jpp.8.AXS3

エラータID: AXSA:2014-309:01

Release date: 
Friday, May 9, 2014 - 18:18
Subject: 
struts-1.2.9-4jpp.8.AXS3
Affected Channels: 
Asianux Server 3 for x86
Asianux Server 3 for x86_64
Severity: 
High
Description: 

Welcome to the Struts Framework! The goal of this project is to provide an open source framework useful in building web applications with Java Servlet and JavaServer Pages (JSP) technology. Struts encourages application architectures based on the Model-View-Controller (MVC) design paradigm, colloquially known as Model 2 in discussions on various servlet and JSP related mailing lists.

Struts includes the following primary areas of functionality: A controller servlet that dispatches requests to appropriate Action classes provided by the application developer. JSP custom tag libraries, and associated support in the controller servlet, that assists developers in creating interactive form-based applications.

Utility classes to support XML parsing, automatic population of JavaBeans properties based on the Java reflection APIs, and internationalization of prompts and messages. Struts is part of the Jakarta Project, sponsored by the Apache Software Foundation. The official Struts home page is at http://jakarta.apache.org/struts.

Security issues fixed with this release:

• CVE-2014-0114
The ActionForm object in Apache Struts 1.x through 1.3.10 allows remote attackers to "manipulate" the ClassLoader and execute arbitrary code via the class parameter, which is passed to the getClass method.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. struts-1.2.9-4jpp.8.AXS3.src.rpm
    MD5: 43cebd5f60731520b91e81bfef8d1dbc
    SHA-256: fd52db4e87935de5683780bf54667da5a4bbb99d802ae667b4f605d678073e3e
    Size: 5.44 MB

Asianux Server 3 for x86
  1. struts-1.2.9-4jpp.8.AXS3.i386.rpm
    MD5: aaa52b0e878f715910d0d308f6eb0eb4
    SHA-256: ffa7d2a71ac6419516f3ac6647d8b780605b00770a53e4b326c8d068ce5da2af
    Size: 0.97 MB

Asianux Server 3 for x86_64
  1. struts-1.2.9-4jpp.8.AXS3.x86_64.rpm
    MD5: e69d9e43be7ddba7830bd430fb843dab
    SHA-256: de7602623e162a8710c957a2ea9d09b2d3215eb4e290926cbec14a274a4fdf44
    Size: 1.09 MB