Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-0422

Опубликовано: 23 янв. 2025
Источник: oracle-oval
Платформа: Oracle Linux 8
Платформа: Oracle Linux 9

Описание

ELSA-2025-0422: java-17-openjdk security update for RHEL 8.6, 8.8, 8.10, 9.4 and 9.5 (MODERATE)

[1:17.0.14.0.7-3.0.1]

  • Add Oracle vendor bug URL [Orabug: 34340155]

[1:17.0.14.0.7-3]

  • Set rpmrelease to 3
  • Revert 'Require tzdata-java 2024b at runtime and for build'

[1:17.0.14.0.7-2]

  • Do not pass nil to _jvmdir macro in cjc logic
  • Related: RHEL-73867

[1:17.0.14.0.7-2]

  • Adapt to newest cjc to fix issue with rpm 4.17
  • Disable copy-jdk-configs for Flatpak builds
  • Remove cjc backward compatibility, to fix when both rpm 4.16 and 4.17 are in transaction
  • Resolves: rhbz#1953923
  • Resolves: RHEL-73867

[1:17.0.14.0.7-2]

  • Update to jdk-17.0.14+7 (GA)
  • Add to .gitignore openjdk-17.0.14+7.tar.xz
  • Set buildver to 7
  • Set is_ga to 1
  • Update sources to openjdk-17.0.14+7.tar.xz
  • Require tzdata-java 2024b at runtime and for build
  • Sync java-17-openjdk-portable.specfile from openjdk-portable-rhel-8
  • Resolves: RHEL-73545
  • ** This tarball is embargoed until 2025-01-21 @ 1pm PT. **

[1:17.0.14.0.1-0.2.ea]

  • Limit Java only tests to one architecture using jdk_test_arch
  • OPENJDK-3185

[1:17.0.14.0.1-0.2.ea]

  • Update to jdk-17.0.14+1 (EA)
  • Add to .gitignore openjdk-17.0.14+1-ea.tar.xz
  • Set updatever to 14
  • Set buildver to 1
  • Set rpmrelease to 2
  • Set is_ga to 0
  • Update sources to openjdk-17.0.14+1-ea.tar.xz
  • Double percent signs consistently throughout comments
  • Set bundled giflib provide version to 5.2.2
  • Set bundled libpng provide version to 1.6.43
  • Warn about bundled provide version bumps and backouts in openjdk_news.sh
  • Remove 0001-8332174-Remove-2-unpaired-RLO-Unicode-characters-in-.patch file
  • Revert: Use component in EPEL and Fedora bug URLs

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

java-17-openjdk-demo-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-demo-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-devel-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-devel-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-headless-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-headless-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-jmods-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-jmods-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-src-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-src-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-static-libs-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-static-libs-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk

17.0.14.0.7-3.0.1.el8

java-17-openjdk-demo

17.0.14.0.7-3.0.1.el8

java-17-openjdk-devel

17.0.14.0.7-3.0.1.el8

java-17-openjdk-headless

17.0.14.0.7-3.0.1.el8

java-17-openjdk-javadoc

17.0.14.0.7-3.0.1.el8

java-17-openjdk-javadoc-zip

17.0.14.0.7-3.0.1.el8

java-17-openjdk-jmods

17.0.14.0.7-3.0.1.el8

java-17-openjdk-src

17.0.14.0.7-3.0.1.el8

java-17-openjdk-static-libs

17.0.14.0.7-3.0.1.el8

Oracle Linux x86_64

java-17-openjdk-demo-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-demo-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-devel-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-devel-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-headless-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-headless-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-jmods-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-jmods-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-src-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-src-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-static-libs-fastdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk-static-libs-slowdebug

17.0.14.0.7-3.0.1.el8

java-17-openjdk

17.0.14.0.7-3.0.1.el8

java-17-openjdk-demo

17.0.14.0.7-3.0.1.el8

java-17-openjdk-devel

17.0.14.0.7-3.0.1.el8

java-17-openjdk-headless

17.0.14.0.7-3.0.1.el8

java-17-openjdk-javadoc

17.0.14.0.7-3.0.1.el8

java-17-openjdk-javadoc-zip

17.0.14.0.7-3.0.1.el8

java-17-openjdk-jmods

17.0.14.0.7-3.0.1.el8

java-17-openjdk-src

17.0.14.0.7-3.0.1.el8

java-17-openjdk-static-libs

17.0.14.0.7-3.0.1.el8

Oracle Linux 9

Oracle Linux aarch64

java-17-openjdk-demo-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-demo-slowdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-devel-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-devel-slowdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-headless-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-headless-slowdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-jmods-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-jmods-slowdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-slowdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-src-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-src-slowdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-static-libs-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-static-libs-slowdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk

17.0.14.0.7-2.0.1.el9

java-17-openjdk-demo

17.0.14.0.7-2.0.1.el9

java-17-openjdk-devel

17.0.14.0.7-2.0.1.el9

java-17-openjdk-headless

17.0.14.0.7-2.0.1.el9

java-17-openjdk-javadoc

17.0.14.0.7-2.0.1.el9

java-17-openjdk-javadoc-zip

17.0.14.0.7-2.0.1.el9

java-17-openjdk-jmods

17.0.14.0.7-2.0.1.el9

java-17-openjdk-src

17.0.14.0.7-2.0.1.el9

java-17-openjdk-static-libs

17.0.14.0.7-2.0.1.el9

Oracle Linux x86_64

java-17-openjdk

17.0.14.0.7-2.0.1.el9

java-17-openjdk-demo

17.0.14.0.7-2.0.1.el9

java-17-openjdk-devel

17.0.14.0.7-2.0.1.el9

java-17-openjdk-headless

17.0.14.0.7-2.0.1.el9

java-17-openjdk-javadoc

17.0.14.0.7-2.0.1.el9

java-17-openjdk-javadoc-zip

17.0.14.0.7-2.0.1.el9

java-17-openjdk-jmods

17.0.14.0.7-2.0.1.el9

java-17-openjdk-src

17.0.14.0.7-2.0.1.el9

java-17-openjdk-static-libs

17.0.14.0.7-2.0.1.el9

java-17-openjdk-demo-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-demo-slowdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-devel-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-devel-slowdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-headless-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-headless-slowdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-jmods-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-jmods-slowdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-slowdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-src-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-src-slowdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-static-libs-fastdebug

17.0.14.0.7-2.0.1.el9

java-17-openjdk-static-libs-slowdebug

17.0.14.0.7-2.0.1.el9

Связанные CVE

Связанные уязвимости

CVSS3: 4.8
ubuntu
5 месяцев назад

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM Enterprise Edition: 20.3.16 and 21.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a ...

CVSS3: 4.8
redhat
5 месяцев назад

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM Enterprise Edition: 20.3.16 and 21.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a...

CVSS3: 4.8
nvd
5 месяцев назад

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM Enterprise Edition: 20.3.16 and 21.3.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data as well as unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a we

CVSS3: 4.8
debian
5 месяцев назад

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...

suse-cvrf
5 месяцев назад

Security update for java-17-openjdk