|
|
Subscribe / Log in / New account

Mageia alert MGASA-2020-0069 (java-1.8.0-openjdk)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2020-0069: Updated java-1.8.0-openjdk packages fix security vulnerabilities
Date:  Thu, 30 Jan 2020 19:29:35 +0100
Message-ID:  <20200130182935.289D79F641@duvel.mageia.org>

MGASA-2020-0069 - Updated java-1.8.0-openjdk packages fix security vulnerabilities Publication date: 30 Jan 2020 URL: https://advisories.mageia.org/MGASA-2020-0069.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-2590, CVE-2020-2583, CVE-2020-2593, CVE-2020-2601, CVE-2020-2604, CVE-2020-2654, CVE-2020-2659 Description: The updated packages fix security vulnerabilities: Improper checks of SASL message properties in GssKrb5Base (Security, 8226352) (CVE-2020-2590) Incorrect exception processing during deserialization in BeanContextSupport (Serialization, 8224909) (CVE-2020-2583) Incorrect isBuiltinStreamHandler causing URL normalization issues (Networking, 8228548) (CVE-2020-2593) Use of unsafe RSA-MD5 checkum in Kerberos TGS (Security, 8229951) (CVE-2020-2601) Serialization filter changes via jdk.serialFilter property modification (Serialization, 8231422) (CVE-2020-2604) Excessive memory usage in OID processing in X.509 certificate parsing (Libraries, 8234037) (CVE-2020-2654) Incomplete enforcement of maxDatagramSockets limit in DatagramChannelImpl (Networking, 8231795) (CVE-2020-2659) References: - https://bugs.mageia.org/show_bug.cgi?id=26075 - https://www.oracle.com/security-alerts/cpujan2020.html#Ap... - https://access.redhat.com/errata/RHSA-2020:0202 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2590 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2583 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2593 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2601 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2604 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2654 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2659 SRPMS: - 7/core/java-1.8.0-openjdk-1.8.0.242-1.b08.2.mga7


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds