Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Fedora 25: FEDORA-2017-03954b6dc4 Critical Timing Attack Fix

fedora
Calendar Grey July 8, 2017
Dist Fedora Esm H88
A resolution for the Timing Channel Attack vulnerability in the jetty-test-helper package of Fedora 25 has been implemented, enhancing system security and integrity
Update to latest upstream release in order to fix CVE-2017-9735

Summary

Unit Testing Support for Jetty (common classes for some unit tests).

Update to latest upstream release in order to fix CVE-2017-9735

[ 1 ] Bug #1464158 - CVE-2017-9735 jetty: Timing channel attack in util/security/Password.java

https://bugzilla.redhat.com/show_bug.cgi?id=1464158

su -c 'dnf upgrade jetty-test-helper' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 25
Version: 3.1
Release: 3.fc25
Summary: Jetty toolchain test helper

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here