Mageia 2023-0037: java/timezone security update
Summary
Improper restrictions in CORBA deserialization. (CVE-2023-21830)
Handshake DoS attack against DTLS connections. (CVE-2023-21835)
Soundbank URL remote loading. (CVE-2023-21843)
References
- https://bugs.mageia.org/show_bug.cgi?id=31452
- https://access.redhat.com/errata/RHSA-2023:0203
- https://access.redhat.com/errata/RHSA-2023:0200
- https://www.oracle.com/security-alerts/cpujan2023.html#AppendixJAVA
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21830
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21835
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21843
Resolution
MGASA-2023-0037 - Updated java/timezone packages fix security vulnerability
SRPMS
- 8/core/java-1.8.0-openjdk-1.8.0.362.b09-1.mga8
- 8/core/java-11-openjdk-11.0.18.0.10-1.mga8
- 8/core/timezone-2022g-1.mga8