Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 486752 (CVE-2013-4310) - dev-java/struts: Multiple vulnerabilities (CVE-2013-{4310,4316})
Summary: dev-java/struts: Multiple vulnerabilities (CVE-2013-{4310,4316})
Status: RESOLVED FIXED
Alias: CVE-2013-4310
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B4 [noglsa]
Keywords:
Depends on: 487280
Blocks:
  Show dependency tree
 
Reported: 2013-10-02 03:47 UTC by GLSAMaker/CVETool Bot
Modified: 2016-02-08 20:11 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2013-10-02 03:47:18 UTC
CVE-2013-4316 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4316):
  Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by
  default, which has unknown impact and attack vectors.

CVE-2013-4310 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-4310):
  Apache Struts 2.0.0 through 2.3.15.1 allows remote attackers to bypass
  access controls via a crafted action: prefix.
Comment 1 Tom Wijsman (TomWij) (RETIRED) gentoo-dev 2013-10-02 23:09:33 UTC
+  02 Oct 2013; Tom Wijsman <TomWij@gentoo.org>
+  +files/struts-2.3.15.2-build.xml-apps-package.patch,
+  +files/struts-2.3.15.2-build.xml-classpath.patch,
+  +files/struts-2.3.15.2-build.xml-manifest.patch,
+  +files/struts-2.3.15.2-build.xml-remove-apps-portlet.patch,
+  +files/struts-2.3.15.2-build.xml-remove-core-and-plugins.patch,
+  +struts-2.3.15.2.ebuild:
+  Version bump to 2.3.15.2; for bug #152352, bug #237146, bug #405931 and bug
+  #486752.

Looks like we are going to need some KEYWORDREQ and STABLEREQ bugs; since it is late and have worked half a day on is, I'll look into that tomorrow. If you want to file them before that, feel free to go ahead.
Comment 2 Patrice Clement gentoo-dev 2016-02-07 11:10:08 UTC
This package has been removed, along with all the struts related ebuilds. See bug 540888.
Comment 3 Mikle Kolyada (RETIRED) archtester Gentoo Infrastructure gentoo-dev Security 2016-02-07 11:20:40 UTC
Should we produce removal GLSA? 

vote: No
Comment 4 Kristian Fiskerstrand (RETIRED) gentoo-dev 2016-02-08 20:11:32 UTC
(In reply to Mikle Kolyada from comment #3)
> Should we produce removal GLSA? 
> 
> vote: No

GLSA Vote: No