The updated packages fix security vulnerabilities: Improper checks of SASL message properties in GssKrb5Base (Security, 8226352) (CVE-2020-2590) . MGASA-2020-0069 - Updated java-1.8.0-openjdk packages fix security vulnerabilities Publication date: 30 Jan 2020 URL: https://advisories.mageia.org/MGASA-2020-0069.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-2590, CVE-2020-2583, CVE-2020-2593, CVE-2020-2601, CVE-2020-2604, CVE-2020-2654, CVE-2020-2659 The updated packages fix security vulnerabilities: Improper checks of SASL message properties in GssKrb5Base (Security, 8226352) (CVE-2020-2590) Incorrect exception processing during deserialization in BeanContextSupport (Serialization, 8224909) (CVE-2020-2583) Incorrect isBuiltinStreamHandler causing URL normalization issues (Networking, 8228548) (CVE-2020-2593) Use of unsafe RSA-MD5 checkum in Kerberos TGS (Security, 8229951) (CVE-2020-2601) Serialization filter changes via jdk.serialFilter property modification (Serialization, 8231422) (CVE-2020-2604) Excessive memory usage in OID processing in X.509 certificate parsing (Libraries, 8234037) (CVE-2020-2654) Incomplete enforcement of maxDatagramSockets limit in DatagramChannelImpl (Networking, 8231795) (CVE-2020-2659) References: - https://bugs.mageia.org/show_bug.cgi?id=26075 - https://www.oracle.com/security-alerts/cpujan2020.html#AppendixJAVA - https://access.redhat.com/errata/RHSA-2020:0202 - https://www.cve.org/CVERecord?id=CVE-2020-2590 - https://www.cve.org/CVERecord?id=CVE-2020-2583 - https://www.cve.org/CVERecord?id=CVE-2020-2593 - https://www.cve.org/CVERecord?id=CVE-2020-2601 - https://www.cve.org/CVERecord?id=CVE-2020-2604 - https://www.cve.org/CVERecord?id=CVE-2020-2654 - https://www.cve.org/CVERecord?id=CVE-2020-2659 SRPMS: - 7/core/java-1.8.0-openjdk-1.8.0.242-1.b08.2.mga7 . Implementing security enhancements for java-1.8.0-openjdk in Mageia to bolster overall system security and ensure integrity.. java update, security enhancements, Mageiapackages, openjdk, patch notes. . LinuxSecurity.com Team
Fix improper checks in deepin-api polkit actions. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-c25a0e7032 2019-06-06 01:05:45.805424 --------------------------------------------------------------------------------Name : deepin-api Product : Fedora 30 Version : 3.17.0 Release : 2.fc30 URL : https://github.com/linuxdeepin/dde-api Summary : Go-lang bingding for dde-daemon Description : Go-lang bingding for dde-daemon. --------------------------------------------------------------------------------Update Information: Fix improper checks in deepin-api polkit actions --------------------------------------------------------------------------------ChangeLog: * Tue May 28 2019 Robin Lee - 3.17.0-2 - Fix a security issue --------------------------------------------------------------------------------References: [ 1 ] Bug #1713957 - Security: improper checks in deepin-api polkit actions https://bugzilla.redhat.com/show_bug.cgi?id=1713957 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-c25a0e7032' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
OpenJDK: Improper field access checks (Hotspot, 8199226) (CVE-2018-3169) * OpenJDK: Incomplete enforcement of the trustURLCodebase restriction (JNDI, 8199177) (CVE-2018-3149) * OpenJDK: Incorrect handling of unsigned attributes in signed Jar manifests (Security, 8194534) (CVE-2018-3136) * OpenJDK: Leak of sensitive header data via HTTP redirect (Networking, 8196902) (CVE-2018-3139) * OpenJ [More...]. Synopsis: Important: java-1.7.0-openjdk security update Advisory ID: SLSA-2018:3409-1 Issue Date: 2018-10-31 CVE Numbers: CVE-2018-3169 CVE-2018-3214 CVE-2018-3139 CVE-2018-3180 CVE-2018-3136 CVE-2018-3149 -- Security Fix(es): * OpenJDK: Improper field access checks (Hotspot, 8199226) (CVE-2018-3169) * OpenJDK: Incomplete enforcement of the trustURLCodebase restriction (JNDI, 8199177) (CVE-2018-3149) * OpenJDK: Incorrect handling of unsigned attributes in signed Jar manifests (Security, 8194534) (CVE-2018-3136) * OpenJDK: Leak of sensitive header data via HTTP redirect (Networking, 8196902) (CVE-2018-3139) * OpenJDK: Missing endpoint identification algorithm check during TLS session resumption (JSSE, 8202613) (CVE-2018-3180) * OpenJDK: Infinite loop in RIFF format reader (Sound, 8205361) (CVE-2018-3214) -- SL6 x86_64 java-1.7.0-openjdk-1.7.0.201-2.6.16.0.el6_10.x86_64.rpm java-1.7.0-openjdk-debuginfo-1.7.0.201-2.6.16.0.el6_10.x86_64.rpm java-1.7.0-openjdk-devel-1.7.0.201-2.6.16.0.el6_10.x86_64.rpm java-1.7.0-openjdk-demo-1.7.0.201-2.6.16.0.el6_10.x86_64.rpm java-1.7.0-openjdk-src-1.7.0.201-2.6.16.0.el6_10.x86_64.rpm i386 java-1.7.0-openjdk-1.7.0.201-2.6.16.0.el6_10.i686.rpm java-1.7.0-openjdk-debuginfo-1.7.0.201-2.6.16.0.el6_10.i686.rpm java-1.7.0-openjdk-devel-1.7.0.201-2.6.16.0.el6_10.i686.rpm java-1.7.0-openjdk-demo-1.7.0.201-2.6.16.0.el6_10.i686.rpm java-1.7.0-openjdk-src-1.7.0.201-2.6.16.0.el6_10.i686.rpm noarch java-1.7.0-openjdk-javadoc-1.7.0.201-2.6.16.0.el6_10.noarch.rpm - Scientific Linux Development Team . Important security updates for java-1.7.0-openjdk tackle various threats in Scientific Linux. Ensure your system is current.. java security, openjdk updates, Scientific Linux advisory, security fixes, Java vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.