MGASA-2019-0241

Source
https://advisories.mageia.org/MGASA-2019-0241.html
Import Source
https://advisories.mageia.org/MGASA-2019-0241.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2019-0241
Related
Published
2019-09-06T21:09:08Z
Modified
2019-09-06T18:59:31Z
Summary
Updated java-1.8.0-openjdk packages fix security vulnerabilities
Details

The updated packages fix several bugs and some security issues:

Side-channel attack risks in Elliptic Curve (EC) cryptography. (CVE-2019-2745)

Insufficient checks of suppressed exceptions in deserialization. (CVE-2019-2762)

Unbounded memory allocation during deserialization in Collections. (CVE-2019-2769)

Insufficient restriction of privileges in AccessController. (CVE-2019-2786)

Missing URL format validation. (CVE-2019-2816)

Missing array bounds check in crypto providers. (CVE-2019-2842)

References
Credits

Affected packages

Mageia:7 / java-1.8.0-openjdk

Package

Name
java-1.8.0-openjdk
Purl
pkg:rpm/mageia/java-1.8.0-openjdk?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.0.222-1.b10.1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / java-1.8.0-openjdk

Package

Name
java-1.8.0-openjdk
Purl
pkg:rpm/mageia/java-1.8.0-openjdk?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.0.222-1.b10.1.mga6

Ecosystem specific

{
    "section": "core"
}