Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Mageia 8: MGASA-2023-0037 Critical: Java/Timezone Security Issues

mageia
Calendar Grey February 7, 2023
Dist Mageia Esm H88
Mageia 2023-0038 releases updates for python/libraries fixing various vulnerabilities such as injection flaws and memory corruption.
Improper restrictions in CORBA deserialization

Summary

Improper restrictions in CORBA deserialization. (CVE-2023-21830)
Handshake DoS attack against DTLS connections. (CVE-2023-21835)
Soundbank URL remote loading. (CVE-2023-21843)

References

- https://bugs.mageia.org/show_bug.cgi?id=31452

- https://access.redhat.com/errata/RHSA-2023:0203

- https://access.redhat.com/errata/RHSA-2023:0200

- https://www.oracle.com/security-alerts/cpujan2023.html#AppendixJAVA

- https://www.cve.org/CVERecord?id=CVE-2023-21830

- https://www.cve.org/CVERecord?id=CVE-2023-21835

- https://www.cve.org/CVERecord?id=CVE-2023-21843

Resolution

SRPMS

- 8/core/java-1.8.0-openjdk-1.8.0.362.b09-1.mga8

- 8/core/java-11-openjdk-11.0.18.0.10-1.mga8

- 8/core/timezone-2022g-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 07 Feb 2023
URL: https://advisories.mageia.org/MGASA-2023-0037.html
Type: security
CVE: CVE-2023-21830, CVE-2023-21835, CVE-2023-21843

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here