Candidate: CVE-2012-0838 PublicDate: 2012-03-02 22:55:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0838 http://jvndb.jvn.jp/jvndb/JVNDB-2012-000012 Description: Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field. Ubuntu-Description: Notes: Bugs: https://issues.apache.org/jira/browse/WW-3668 Priority: medium Discovered-by: Assigned-to: CVSS: Patches_libstruts1.2-java: upstream_libstruts1.2-java: released (2.2.3.1) hardy_libstruts1.2-java: ignored (reached end-of-life) lucid_libstruts1.2-java: ignored (reached end-of-life) maverick_libstruts1.2-java: ignored (reached end-of-life) natty_libstruts1.2-java: ignored (reached end-of-life) oneiric_libstruts1.2-java: ignored (reached end-of-life) precise_libstruts1.2-java: ignored (reached end-of-life) precise/esm_libstruts1.2-java: DNE (precise was needs-triage) quantal_libstruts1.2-java: ignored (reached end-of-life) raring_libstruts1.2-java: ignored (reached end-of-life) saucy_libstruts1.2-java: ignored (reached end-of-life) trusty_libstruts1.2-java: not-affected (code not present) trusty/esm_libstruts1.2-java: DNE (trusty was not-affected [code not present]) utopic_libstruts1.2-java: ignored (reached end-of-life) vivid_libstruts1.2-java: DNE vivid/stable-phone-overlay_libstruts1.2-java: DNE vivid/ubuntu-core_libstruts1.2-java: DNE wily_libstruts1.2-java: DNE xenial_libstruts1.2-java: DNE yakkety_libstruts1.2-java: DNE zesty_libstruts1.2-java: DNE artful_libstruts1.2-java: DNE bionic_libstruts1.2-java: DNE cosmic_libstruts1.2-java: DNE devel_libstruts1.2-java: DNE