Debian Security Advisory

DLA-57-1 libstruts1.2-java -- LTS security update

Date Reported:
17 Sep 2014
Affected Packages:
libstruts1.2-java
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2014-0114.
More information:

It was discovered that missing access checks in the Struts ActionForm object could result in the execution of arbitrary code. This update fixes this problem.

For Debian 6 Squeeze, these issues have been fixed in libstruts1.2-java version 1.2.9-4+deb6u1