Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Scientific Linux: SLSA-2014:0474-1 Critical Struts Remote Code Execution

Scientific Large Esm H446
Important: struts security update
Date: Tue, 6 May 2014 10:41:52 -0500
Reply-To: Bonnie King 
Sender: Security Errata for Scientific Linux
 
From: Bonnie King 
Subject: FASTBUGS for SL 6x i386, x86_64 now available
Comments: To: This email address is being protected from spambots. You need JavaScript enabled to view it.
In-Reply-To: <535FC77F.9080201@fnal.gov>
MIME-Version: 1.0

The following FASTBUGS have been uploaded to

i386:
device-mapper-multipath-0.4.9-72.el6_5.2.i686.rpm
device-mapper-multipath-libs-0.4.9-72.el6_5.2.i686.rpm
device-mapper-persistent-data-0.2.8-4.el6_5.i686.rpm
ethtool-3.5-1.4.el6_5.i686.rpm
kpartx-0.4.9-72.el6_5.2.i686.rpm
nss_db-2.2.3-0.5.pre1.el6_5.1.i686.rpm
openscap-1.0.8-1.el6_5.i686.rpm
openscap-content-1.0.8-1.el6_5.noarch.rpm
openscap-devel-1.0.8-1.el6_5.i686.rpm
openscap-engine-sce-1.0.8-1.el6_5.i686.rpm
openscap-engine-sce-devel-1.0.8-1.el6_5.i686.rpm
openscap-extra-probes-1.0.8-1.el6_5.i686.rpm
openscap-python-1.0.8-1.el6_5.i686.rpm
openscap-utils-1.0.8-1.el6_5.i686.rpm
perl-Crypt-SSLeay-0.57-17.el6.i686.rpm
rsync-3.0.6-12.el6.i686.rpm
sos-2.2-47.el6_5.1.noarch.rpm
spice-glib-0.20-11.el6_5.1.i686.rpm
spice-glib-devel-0.20-11.el6_5.1.i686.rpm
spice-gtk-0.20-11.el6_5.1.i686.rpm
spice-gtk-devel-0.20-11.el6_5.1.i686.rpm
spice-gtk-python-0.20-11.el6_5.1.i686.rpm
spice-gtk-tools-0.20-11.el6_5.1.i686.rpm

x86_64:
device-mapper-multipath-0.4.9-72.el6_5.2.x86_64.rpm
device-mapper-multipath-libs-0.4.9-72.el6_5.2.x86_64.rpm
device-mapper-persistent-data-0.2.8-4.el6_5.x86_64.rpm
ethtool-3.5-1.4.el6_5.x86_64.rpm
kpartx-0.4.9-72.el6_5.2.x86_64.rpm
nss_db-2.2.3-0.5.pre1.el6_5.1.i686.rpm
nss_db-2.2.3-0.5.pre1.el6_5.1.x86_64.rpm
openscap-1.0.8-1.el6_5.i686.rpm
openscap-1.0.8-1.el6_5.x86_64.rpm
openscap-content-1.0.8-1.el6_5.noarch.rpm
openscap-devel-1.0.8-1.el6_5.i686.rpm
openscap-devel-1.0.8-1.el6_5.x86_64.rpm
openscap-engine-sce-1.0.8-1.el6_5.x86_64.rpm
openscap-engine-sce-devel-1.0.8-1.el6_5.x86_64.rpm
openscap-extra-probes-1.0.8-1.el6_5.x86_64.rpm
openscap-python-1.0.8-1.el6_5.x86_64.rpm
openscap-utils-1.0.8-1.el6_5.x86_64.rpm
perl-Crypt-SSLeay-0.57-17.el6.x86_64.rpm
rsync-3.0.6-12.el6.x86_64.rpm
sos-2.2-47.el6_5.1.noarch.rpm
spice-glib-0.20-11.el6_5.1.i686.rpm
spice-glib-0.20-11.el6_5.1.x86_64.rpm
spice-glib-devel-0.20-11.el6_5.1.i686.rpm
spice-glib-devel-0.20-11.el6_5.1.x86_64.rpm
spice-gtk-0.20-11.el6_5.1.i686.rpm
spice-gtk-0.20-11.el6_5.1.x86_64.rpm
spice-gtk-devel-0.20-11.el6_5.1.i686.rpm
spice-gtk-devel-0.20-11.el6_5.1.x86_64.rpm
spice-gtk-python-0.20-11.el6_5.1.x86_64.rpm
spice-gtk-tools-0.20-11.el6_5.1.x86_64.rpm
Date: Wed, 7 May 2014 14:40:51 +0000
Reply-To: scientific-linux-users@
Sender: Security Errata for Scientific Linux
 
From: Pat Riehecky 
Subject: Security ERRATA Important: struts on SL5.x i386/x86_64
MIME-Version: 1.0

Synopsis: Important: struts security update
Advisory ID: SLSA-2014:0474-1
Issue Date: 2014-05-07
CVE Numbers: CVE-2014-0114
--

It was found that the Struts 1 ActionForm object allowed access to the
'class' parameter, which is directly mapped to the getClass() method. A
remote attacker could use this flaw to manipulate the ClassLoader used by
an application server running Struts 1. This could lead to remote code
execution under certain conditions. (CVE-2014-0114)

All running applications using struts must be restarted for this update to
take effect.
--

SL5
 x86_64
 struts-1.2.9-4jpp.8.el5_10.x86_64.rpm
 struts-debuginfo-1.2.9-4jpp.8.el5_10.x86_64.rpm
 struts-javadoc-1.2.9-4jpp.8.el5_10.x86_64.rpm
 struts-manual-1.2.9-4jpp.8.el5_10.x86_64.rpm
 struts-webapps-tomcat5-1.2.9-4jpp.8.el5_10.x86_64.rpm
 i386
 struts-1.2.9-4jpp.8.el5_10.i386.rpm
 struts-debuginfo-1.2.9-4jpp.8.el5_10.i386.rpm
 struts-javadoc-1.2.9-4jpp.8.el5_10.i386.rpm
 struts-manual-1.2.9-4jpp.8.el5_10.i386.rpm
 struts-webapps-tomcat5-1.2.9-4jpp.8.el5_10.i386.rpm

- Scientific Linux Development Team