-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: OpenJDK 8u292 Windows Builds release and security update
Advisory ID:       RHSA-2021:1445-01
Product:           OpenJDK
Advisory URL:      https://access.redhat.com/errata/RHSA-2021:1445
Issue date:        2021-04-28
Keywords:          openjdk,windows
Cross references:  RHSA-2021:70386-01
CVE Names:         CVE-2021-2161 CVE-2021-2163 
====================================================================
1. Summary:

The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available for
Windows.

Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and
the OpenJDK 8 Java Software Development Kit.

This release of the Red Hat build of OpenJDK 8 (1.8.0.292) for Windows
serves as a replacement for the Red Hat build of OpenJDK 8 (1.8.0.282) and
includes security and bug fixes, and enhancements. For further information,
refer to the release notes linked to in the References section.

Security Fix(es):

* OpenJDK: Incorrect handling of partially quoted arguments in
ProcessBuilder on Windows (Libraries, 8250568) (CVE-2021-2161)

* OpenJDK: Incomplete enforcement of JAR signing disabled algorithms
(Libraries, 8249906) (CVE-2021-2163)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/documentation/en-us/openjdk/8/html/installing_and
_using_openjdk_8_for_windows/index

4. Bugs fixed (https://bugzilla.redhat.com/):

1951217 - CVE-2021-2163 OpenJDK: Incomplete enforcement of JAR signing disabled algorithms (Libraries, 8249906)
1951231 - CVE-2021-2161 OpenJDK: Incorrect handling of partially quoted arguments in ProcessBuilder on Windows (Libraries, 8250568)

5. References:

https://access.redhat.com/security/cve/CVE-2021-2161
https://access.redhat.com/security/cve/CVE-2021-2163
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=core.service.openjdk&version=1.8.0.292
https://access.redhat.com/documentation/en-us/openjdk/8/html/installing_and_using_openjdk_8_for_windows/index
https://access.redhat.com/documentation/en-us/openjdk/8/html/troubleshooting_openjdk_8_for_windows/index
https://openjdk.org/groups/vulnerability/advisories/2021-04-20

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYIlW99zjgjWX9erEAQhf2w//Y2ma/p8XNZzkqypaS9tLt4O5WTaLkZ84
p9YgmTYdaXQqcqoxeMkgWeoDDncbSfa1rK8Gx+zDY+wtqiGP3RTWcPZ6qzyOdHfM
h2AzuDxjtoWqk0aIzomzzNUitC+EAicJ/GeUzqaVqlStopjH3Yfz+zn2nL/40JNI
BX88A7c9vxtZXlaYqLNn3qOE5nB2fKLDYDkYkb3iK0hbJHONQI1m3gIVxh3dyCA3
vo6b5Mh5s1gk6Hud+YObiXpbYnC++obSHYJW0eeMk6uJnocTn1GodS1CFAszquqM
DhG2wUuMooG94GRbZVvsfNfKHCJ7/kCU/ViVs1GCuOhkhBlklWNZg5KBAB8hLKug
Xh9u6NcYidM0mTd/mwhjkfptZs+cqxLRoo2aSAwwmxmOauv6PXwExBnTqKgYipjD
4e3uvd28U6AD1zI/VmWQsE5BCGpy6pPeFWmbHzoVTZdWLihxA9Hj/BvX2GNj7R9p
psytP80l2Dx01ppCP0vUf85KmmLVxklb0j7zmxCxYsZk/T7p9h3/Hf8LtvHHDr35
UO3DwT4LXbrMiGZByI/QuD4EW5sEZd7a+w3obbTmoc5S0dFPLals3OdB20R5mixu
69/A8XxOQ4XlTq+SkhBLpjVSnyWjsfeNsBIFYS8m8YW4f+U2/6GhLNbaaJ2PQiGW
tyiQ9zRCIe4=V8tu
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2021-1445:01 Moderate: OpenJDK 8u292 Windows Builds release

The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available for Windows

Summary

The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.
This release of the Red Hat build of OpenJDK 8 (1.8.0.292) for Windows serves as a replacement for the Red Hat build of OpenJDK 8 (1.8.0.282) and includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.
Security Fix(es):
* OpenJDK: Incorrect handling of partially quoted arguments in ProcessBuilder on Windows (Libraries, 8250568) (CVE-2021-2161)
* OpenJDK: Incomplete enforcement of JAR signing disabled algorithms (Libraries, 8249906) (CVE-2021-2163)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/documentation/en-us/openjdk/8/html/installing_and _using_openjdk_8_for_windows/index

References

https://access.redhat.com/security/cve/CVE-2021-2161 https://access.redhat.com/security/cve/CVE-2021-2163 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=core.service.openjdk&version=1.8.0.292 https://access.redhat.com/documentation/en-us/openjdk/8/html/installing_and_using_openjdk_8_for_windows/index https://access.redhat.com/documentation/en-us/openjdk/8/html/troubleshooting_openjdk_8_for_windows/index https://openjdk.org/groups/vulnerability/advisories/2021-04-20

Package List


Severity
Advisory ID: RHSA-2021:1445-01
Product: OpenJDK
Advisory URL: https://access.redhat.com/errata/RHSA-2021:1445
Issued Date: : 2021-04-28
Keywords: openjdk,windows
Cross references: RHSA-2021:70386-01
CVE Names: CVE-2021-2161 CVE-2021-2163

Topic

The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available forWindows.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

1951217 - CVE-2021-2163 OpenJDK: Incomplete enforcement of JAR signing disabled algorithms (Libraries, 8249906)

1951231 - CVE-2021-2161 OpenJDK: Incorrect handling of partially quoted arguments in ProcessBuilder on Windows (Libraries, 8250568)


Related News