Alerts This Week
Warning Icon 1 1,149
Alerts This Week
Warning Icon 1 1,149

Ubuntu 20.04 LTS Security: USN-4453-1 OpenJDK 8 Issues Report

ubuntu
Calendar Grey August 5, 2020
Dist Ubuntu Esm H88
Ubuntu 22.04, 20.04, and 18.04 LTS are affected by several critical OpenJDK 11 vulnerabilities requiring immediate patching.
Several security issues were fixed in OpenJDK 8.

Summary

Several security issues were fixed in OpenJDK 8.

Software Description:

- openjdk-8: Open Source Java implementation

Details:

Johannes Kuhn discovered that OpenJDK 8 incorrectly handled access control

contexts. An attacker could possibly use this issue to execute arbitrary

code. (CVE-2020-14556)

Philippe Arteau discovered that OpenJDK 8 incorrectly verified names in

TLS server's X.509 certificates. An attacker could possibly use this

issue to obtain sensitive information. (CVE-2020-14577)

It was discovered that OpenJDK 8 incorrectly handled exceptions in

DerInputStream class and in the DerValue.equals() method. An attacker

could possibly use this issue to cause a denial of service.

(CVE-2020-14578, CVE-2020-14579)

It was discovered that OpenJDK 8 incorrectly handled image files. An

attacker could possibly use this issue to obtain sensitive information.

(CVE-2020-14581)

Markus Loewe discovered that OpenJDK 8 incorrectly handled concurrent

access in java.nio.Buffer class. An at...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  openjdk-8-jdk                   8u265-b01-0ubuntu2~20.04
  openjdk-8-jre                   8u265-b01-0ubuntu2~20.04
  openjdk-8-jre-headless          8u265-b01-0ubuntu2~20.04
  openjdk-8-jre-zero              8u265-b01-0ubuntu2~20.04

Ubuntu 18.04 LTS:
  openjdk-8-jdk                   8u265-b01-0ubuntu2~18.04
  openjdk-8-jre                   8u265-b01-0ubuntu2~18.04
  openjdk-8-jre-headless          8u265-b01-0ubuntu2~18.04
  openjdk-8-jre-zero              8u265-b01-0ubuntu2~18.04

Ubuntu 16.04 LTS:
  openjdk-8-jdk                   8u265-b01-0ubuntu2~16.04
  openjdk-8-jre                   8u265-b01-0ubuntu2~16.04
  openjdk-8-jre-headless          8u265-b01-0ubuntu2~16.04
  openjdk-8-jre-jamvm             8u265-b01-0ubuntu2~16.04
  openjdk-8-jre-zero              8u265-b01-0ubuntu2~16.04

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any Java
applications or applets to make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4453-1

CVE-2020-14556, CVE-2020-14577, CVE-2020-14578, CVE-2020-14579,

CVE-2020-14581, CVE-2020-14583, CVE-2020-14593, CVE-2020-14621

Severity
important
Lowest
Low
Medium
High
Critical

August 05, 2020

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here