Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2023-5733

Опубликовано: 02 нояб. 2023
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2023-5733: java-1.8.0-openjdk security update (MODERATE)

[1:1.8.0.392.b08-3.0.1]

  • Update to shenandoah-jdk8u392-b08 (GA)
  • OpenJDK: segmentation fault in ciMethodBlocks (CVE-2022-40433)
  • OpenJDK: IOR deserialization issue in CORBA (8303384) (CVE-2023-22067)
  • OpenJDK: certificate path validation issue during client authentication (8309966) (CVE-2023-22081)
  • A maximum signature file size property, jdk.jar.maxSignatureFileSize, was introduced in the 8u382 release of OpenJDK by JDK-8300596, with a default of 8 MB. This default proved to be too small for some JAR files. This release, 8u392, increases it to 16 MB. (RHEL-13593)

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

java-1.8.0-openjdk

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-demo

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-demo-fastdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-demo-slowdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-devel

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-devel-fastdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-devel-slowdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-fastdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-headless

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-headless-fastdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-headless-slowdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-javadoc

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-javadoc-zip

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-slowdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-src

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-src-fastdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-src-slowdebug

1.8.0.392.b08-3.0.1.el9

Oracle Linux x86_64

java-1.8.0-openjdk

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-demo

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-demo-fastdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-demo-slowdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-devel

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-devel-fastdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-devel-slowdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-fastdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-headless

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-headless-fastdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-headless-slowdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-javadoc

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-javadoc-zip

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-slowdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-src

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-src-fastdebug

1.8.0.392.b08-3.0.1.el9

java-1.8.0-openjdk-src-slowdebug

1.8.0.392.b08-3.0.1.el9

Связанные уязвимости

oracle-oval
больше 1 года назад

ELSA-2023-5731: java-1.8.0-openjdk security update (MODERATE)

CVSS3: 4.9
redhat
почти 2 года назад

A vulnerability was found in OpenJDK. This issue occurs in the ciMethodBlocks::make_block_at function in OpenJDK (HotSpot VM) 8 (11 and 17 are fixed starting from 11.0.17 and 17.0.5 respectively), and may allow an attacker to cause a denial of service.

nvd
почти 2 года назад

Rejected reason: ** REJECT ** This CVE ID has been rejected by its CNA as it was not a security issue.

oracle-oval
больше 1 года назад

ELSA-2023-5761: java-1.8.0-openjdk security update (MODERATE)

suse-cvrf
больше 1 года назад

Security update for java-1_8_0-openj9