Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

Ubuntu 20.04 & 18.04: USN-4433-1 Critical: OpenJDK Security Issues

ubuntu
Calendar Grey July 23, 2020
Dist Ubuntu Esm H88
The Ubuntu Security Announcement USN-4441-2 covers various vulnerabilities in OpenJDK that impact Ubuntu 18.04 and 20.04 LTS platforms.
Several security issues were fixed in OpenJDK.

Summary

Several security issues were fixed in OpenJDK.

Software Description:

- openjdk-lts: Open Source Java implementation

Details:

Johannes Kuhn discovered that OpenJDK incorrectly handled access control

contexts. An attacker could possibly use this issue to execute arbitrary

code. (CVE-2020-14556)

It was discovered that OpenJDK incorrectly handled memory allocation when

reading TIFF image files. An attacker could possibly use this issue to

cause a denial of service. (CVE-2020-14562)

It was discovered that OpenJDK incorrectly handled input data. An

attacker could possibly use this issue to insert, edit or obtain

sensitive information. (CVE-2020-14573)

Philippe Arteau discovered that OpenJDK incorrectly verified names in

TLS server's X.509 certificates. An attacker could possibly use this

issue to obtain sensitive information. (CVE-2020-14577)

It was discovered that OpenJDK incorrectly handled image files. An

attacker could possibly use this issue to obtain sensitive information.

(...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  openjdk-11-jdk                  11.0.8+10-0ubuntu1~20.04
  openjdk-11-jre                  11.0.8+10-0ubuntu1~20.04
  openjdk-11-jre-headless         11.0.8+10-0ubuntu1~20.04
  openjdk-11-jre-zero             11.0.8+10-0ubuntu1~20.04

Ubuntu 18.04 LTS:
  openjdk-11-jdk                  11.0.8+10-0ubuntu1~18.04.1
  openjdk-11-jre                  11.0.8+10-0ubuntu1~18.04.1
  openjdk-11-jre-headless         11.0.8+10-0ubuntu1~18.04.1
  openjdk-11-jre-zero             11.0.8+10-0ubuntu1~18.04.1

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any Java
applications or applets to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4433-1

CVE-2020-14556, CVE-2020-14562, CVE-2020-14573, CVE-2020-14577,

CVE-2020-14581, CVE-2020-14583, CVE-2020-14593, CVE-2020-14621

Severity
critical
Lowest
Low
Medium
High
Critical

July 23, 2020

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here