-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Important: OpenJDK 8u302 Security Update for Portable Linux Builds
Advisory ID:       RHSA-2021:2778-01
Product:           OpenJDK
Advisory URL:      https://access.redhat.com/errata/RHSA-2021:2778
Issue date:        2021-07-22
Keywords:          openjdk,linux
CVE Names:         CVE-2021-2341 CVE-2021-2369 CVE-2021-2388 
====================================================================
1. Summary:

The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available for
portable Linux.

Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.

2. Description:

The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and
the OpenJDK 8 Java Software Development Kit.

This release of the Red Hat build of OpenJDK 8 (1.8.0.302) for portable
Linux serves as a replacement for the Red Hat build of OpenJDK 8
(1.8.0.292) and includes security and bug fixes, and enhancements. For
further information, refer to the release notes linked to in the References
section.

Security Fix(es):

* OpenJDK: FTP PASV command response can cause FtpClient to connect to
arbitrary host (Networking, 8258432) (CVE-2021-2341)

* OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF
files (Library, 8260967) (CVE-2021-2369)

* OpenJDK: Incorrect comparison during range check elimination (Hotspot,
8264066) (CVE-2021-2388)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/documentation/en-us/openjdk/8/html/installing_and
_using_openjdk_8_for_rhel/installing-openjdk8-on-rhel#installing-jdk8-on-rh
el-using-archive

4. Bugs fixed (https://bugzilla.redhat.com/):

1982874 - CVE-2021-2341 OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432)
1982879 - CVE-2021-2369 OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967)
1983075 - CVE-2021-2388 OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066)

5. References:

https://access.redhat.com/security/cve/CVE-2021-2341
https://access.redhat.com/security/cve/CVE-2021-2369
https://access.redhat.com/security/cve/CVE-2021-2388
https://access.redhat.com/security/updates/classification/#important

6. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBYPmI6NzjgjWX9erEAQi7Hw/9EKCY1gSnpARSItPQz96LLIswfP6MpZuS
+t9E2kz3yfOFviMsaRISts8HXNw+3NAYIXpTu1X+vz/jW5gkWyyDPchB6eaLnRlV
pfS+kFLL+AaH65+LCASjz9u7ibovwVrgIP/UXBnacct9it0lF3wz87QqTki2Gn7I
1QR7utm+0V4ohoQ60nOQU3J3tAXZf6CohE3pVVL5vKqGGsmF8S18ZPlWBfNvzKST
bGFLXlmd+Kgu1LQuVzFpjOu2ueR8+o3uaUiv5mxodPiQsDKW6t3peoIkddh8pt78
myAwnctgTW0Det1saxdqzXa6pT2S6Vu6UV/Z4VNHt+jV5MYnbeWqqlRxzCsmoMGL
7DI6l4bEzf713XzLy3eQv3KAFYg7Bxb2dUcdW8XbVstDRnEiIb5W7Ui1BDA6wSHg
Ubt754UhhqRyt2GgY8InEyssXSfU0aAsQjLNfQqIWxTpPlN6x6nWpQ0laqZHf1lG
hTCwlndMK0QpZeZ6+P2YnC20quWiixKz262VjLGr4j35jcxs/eIlpA0fsTnDEm/2
rDgr6YkwSCL1s6dg1tiApSem01YSVUtfwRDcxZtxjtLJhMZNgT4s+sB/zkz0hJdp
xJ+aFyzeHuA7loQ5kGTV+I6IlzIlDcANZycthUtEe08c5fj5/GDeWQYv8t3xhIkK
peptLFzjVn0=HOkt
-----END PGP SIGNATURE-----

--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2021-2778:01 Important: OpenJDK 8u302 Security Update for

The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available for portable Linux

Summary

The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.
This release of the Red Hat build of OpenJDK 8 (1.8.0.302) for portable Linux serves as a replacement for the Red Hat build of OpenJDK 8 (1.8.0.292) and includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section.
Security Fix(es):
* OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) (CVE-2021-2341)
* OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) (CVE-2021-2369)
* OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066) (CVE-2021-2388)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/documentation/en-us/openjdk/8/html/installing_and _using_openjdk_8_for_rhel/installing-openjdk8-on-rhel#installing-jdk8-on-rh el-using-archive

References

https://access.redhat.com/security/cve/CVE-2021-2341 https://access.redhat.com/security/cve/CVE-2021-2369 https://access.redhat.com/security/cve/CVE-2021-2388 https://access.redhat.com/security/updates/classification/#important

Package List


Severity
Advisory ID: RHSA-2021:2778-01
Product: OpenJDK
Advisory URL: https://access.redhat.com/errata/RHSA-2021:2778
Issued Date: : 2021-07-22
Keywords: openjdk,linux
CVE Names: CVE-2021-2341 CVE-2021-2369 CVE-2021-2388

Topic

The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available forportable Linux.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

1982874 - CVE-2021-2341 OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432)

1982879 - CVE-2021-2369 OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967)

1983075 - CVE-2021-2388 OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066)


Related News