MGASA-2024-0319

Source
https://advisories.mageia.org/MGASA-2024-0319.html
Import Source
https://advisories.mageia.org/MGASA-2024-0319.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2024-0319
Related
Published
2024-09-27T17:21:51Z
Modified
2024-09-30T19:41:56Z
Summary
Updated java-1.8.0-openjdk, java-11-openjdk, java-17-openjdk, & java-latest-openjdk packages fix security vulnerabilities
Details

Potential UTF8 size overflow. (CVE-2024-21131) Excessive symbol length can lead to infinite loop. (CVE-2024-21138) Range Check Elimination (RCE) pre-loop limit overflow. (CVE-2024-21140) Pack200 increase loading time due to improper header validation. (CVE-2024-21144) Out-of-bounds access in 2D image handling. (CVE-2024-21145) RangeCheckElimination array index overflow. (CVE-2024-21147)

References
Credits

Affected packages

Mageia:9 / java-1.8.0-openjdk

Package

Name
java-1.8.0-openjdk
Purl
pkg:rpm/mageia/java-1.8.0-openjdk?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.0.422.b05-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / java-11-openjdk

Package

Name
java-11-openjdk
Purl
pkg:rpm/mageia/java-11-openjdk?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.0.24.0.8-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / java-17-openjdk

Package

Name
java-17-openjdk
Purl
pkg:rpm/mageia/java-17-openjdk?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
17.0.12.0.7-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / java-latest-openjdk

Package

Name
java-latest-openjdk
Purl
pkg:rpm/mageia/java-latest-openjdk?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
22.0.2.0.9-1.rolling.1.mga9

Ecosystem specific

{
    "section": "core"
}