Mageia 2019-0241: java-1.8.0-openjdk security update
Summary
The updated packages fix several bugs and some security issues:
Side-channel attack risks in Elliptic Curve (EC) cryptography.
(CVE-2019-2745)
Insufficient checks of suppressed exceptions in deserialization.
(CVE-2019-2762)
Unbounded memory allocation during deserialization in Collections.
(CVE-2019-2769)
Insufficient restriction of privileges in AccessController.
(CVE-2019-2786)
Missing URL format validation. (CVE-2019-2816)
Missing array bounds check in crypto providers. (CVE-2019-2842)
References
- https://bugs.mageia.org/show_bug.cgi?id=25172
- https://access.redhat.com/errata/RHSA-2019:1816
- https://www.oracle.com/security-alerts/cpujul2019.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2745
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2762
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2769
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2786
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2816
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2842
Resolution
MGASA-2019-0241 - Updated java-1.8.0-openjdk packages fix security vulnerabilities
SRPMS
- 7/core/java-1.8.0-openjdk-1.8.0.222-1.b10.1.mga7
- 6/core/java-1.8.0-openjdk-1.8.0.222-1.b10.1.mga6