Mageia 2018-0436: java-1.8.0-openjdk security update
Summary
Updated java-1.8.0-openjdk packages fix security vulnerabilities:
Incorrect handling of unsigned attributes in singed Jar manifests
(Security, 8194534) (CVE-2018-3136).
Leak of sensitive header data via HTTP redirect (Networking, 8196902)
(CVE-2018-3139).
Incomplete enforcement of the trustURLCodebase restriction
(JNDI, 8199177) (CVE-2018-3149).
Improper field access checks (Hotspot, 8199226) (CVE-2018-3169).
Missing endpoint identification algorithm check during TLS session
resumption (JSSE, 8202613) (CVE-2018-3180).
Unrestricted access to scripting engine (Scripting, 8202936)
(CVE-2018-3183).
Infinite loop in RIFF format reader (Sound, 8205361) (CVE-2018-3214).
References
- https://bugs.mageia.org/show_bug.cgi?id=23718
- https://www.oracle.com/security-alerts/cpuoct2018.html
- https://access.redhat.com/errata/RHSA-2018:2942
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3136
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3139
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3149
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3169
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3180
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3183
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3214
Resolution
MGASA-2018-0436 - Updated java-1.8.0-openjdk packages fix security vulnerabilities
SRPMS
- 6/core/java-1.8.0-openjdk-1.8.0.191-1.b12.1.mga6