MGASA-2023-0037 - Updated java/timezone packages fix security vulnerability

Publication date: 07 Feb 2023
URL: https://advisories.mageia.org/MGASA-2023-0037.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2023-21830,
     CVE-2023-21835,
     CVE-2023-21843

Improper restrictions in CORBA deserialization. (CVE-2023-21830)

Handshake DoS attack against DTLS connections. (CVE-2023-21835)

Soundbank URL remote loading. (CVE-2023-21843)

References:
- https://bugs.mageia.org/show_bug.cgi?id=31452
- https://access.redhat.com/errata/RHSA-2023:0203
- https://access.redhat.com/errata/RHSA-2023:0200
- https://www.oracle.com/security-alerts/cpujan2023.html#AppendixJAVA
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21830
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21835
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21843

SRPMS:
- 8/core/java-1.8.0-openjdk-1.8.0.362.b09-1.mga8
- 8/core/java-11-openjdk-11.0.18.0.10-1.mga8
- 8/core/timezone-2022g-1.mga8

Mageia 2023-0037: java/timezone security update

Improper restrictions in CORBA deserialization

Summary

Improper restrictions in CORBA deserialization. (CVE-2023-21830)
Handshake DoS attack against DTLS connections. (CVE-2023-21835)
Soundbank URL remote loading. (CVE-2023-21843)

References

- https://bugs.mageia.org/show_bug.cgi?id=31452

- https://access.redhat.com/errata/RHSA-2023:0203

- https://access.redhat.com/errata/RHSA-2023:0200

- https://www.oracle.com/security-alerts/cpujan2023.html#AppendixJAVA

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21830

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21835

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21843

Resolution

MGASA-2023-0037 - Updated java/timezone packages fix security vulnerability

SRPMS

- 8/core/java-1.8.0-openjdk-1.8.0.362.b09-1.mga8

- 8/core/java-11-openjdk-11.0.18.0.10-1.mga8

- 8/core/timezone-2022g-1.mga8

Severity
Publication date: 07 Feb 2023
URL: https://advisories.mageia.org/MGASA-2023-0037.html
Type: security
CVE: CVE-2023-21830, CVE-2023-21835, CVE-2023-21843

Related News