Candidate: CVE-2016-4465 PublicDate: 2016-07-04 22:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4465 https://struts.apache.org/docs/s2-041.html Description: The URLValidator class in Apache Struts 2 2.3.20 through 2.3.28.1 and 2.5.x before 2.5.1 allows remote attackers to cause a denial of service via a null value for a URL field. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: ASAI Ken Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L [5.3 MEDIUM] Patches_libstruts1.2-java: upstream_libstruts1.2-java: released (2.3.29, 2.5.1) precise_libstruts1.2-java: ignored (reached end-of-life) precise/esm_libstruts1.2-java: DNE (precise was needed) trusty_libstruts1.2-java: ignored (reached end-of-life) trusty/esm_libstruts1.2-java: DNE (trusty was needed) vivid/stable-phone-overlay_libstruts1.2-java: DNE vivid/ubuntu-core_libstruts1.2-java: DNE wily_libstruts1.2-java: DNE xenial_libstruts1.2-java: DNE yakkety_libstruts1.2-java: DNE zesty_libstruts1.2-java: DNE artful_libstruts1.2-java: DNE bionic_libstruts1.2-java: DNE cosmic_libstruts1.2-java: DNE disco_libstruts1.2-java: DNE devel_libstruts1.2-java: DNE