Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : jdom Product : Fedora 40 Version : 1.1.3 Release : 37.fc40 URL : http://www.jdom.org/ Summary : Java alternative to DOM and SAX Description : JDOM is, quite simply, a Java representation of an XML document. JDOM provides a way to represent that document for easy and efficient reading, manipulation, and writing. It has a straightforward API, is a lightweight and fast, and is optimized for the Java programmer. It's an alternative to DOM and SAX, although it integrates well with both DOM and SAX. -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 1.1.3-37 - Rebuilt for java-21-openjdk as system jdk * Tue Feb 20 2024 Marian Koncek - 1.1.3-36 - Update Java source/target to 1.8 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails tobuild with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 - CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for jdom ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:3547-1 Rating: important References: #1187446 Cross-References: CVE-2021-33813 CVSS scores: CVE-2021-33813 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVE-2021-33813 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: SUSE CaaS Platform 4.0 SUSE Enterprise Storage 6 SUSE Linux Enterprise High Performance Computing 15-ESPOS SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise Server 15-SP1-BCL SUSE Linux Enterprise Server 15-SP1-LTSS SUSE Linux Enterprise Server for SAP 15 SUSE Linux Enterprise Server for SAP 15-SP1 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for jdom fixes the following issues: - CVE-2021-33813: Fixed XXE issue in SAXBuilder can cause a denial of service via a crafted HTTP request (bsc#1187446). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15-SP1: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP1-2022-3547=1 - SUSE Linux Enterprise Server for SAP 15: zypper in -t patchSUSE-SLE-Product-SLES_SAP-15-2022-3547=1 - SUSE Linux Enterprise Server 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-LTSS-2022-3547=1 - SUSE Linux Enterprise Server 15-SP1-BCL: zypper in -t patch SUSE-SLE-Product-SLES-15-SP1-BCL-2022-3547=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2022-3547=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-LTSS-2022-3547=1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-SP1-ESPOS-2022-3547=1 - SUSE Linux Enterprise High Performance Computing 15-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-2022-3547=1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-2022-3547=1 - SUSE Enterprise Storage 6: zypper in -t patch SUSE-Storage-6-2022-3547=1 - SUSE CaaS Platform 4.0: To install this update, use the SUSE CaaS Platform 'skuba' tool. It will inform you if it detects new updates and let you then trigger updating of the complete cluster in a controlled way. Package List: - SUSE Linux Enterprise Server for SAP 15-SP1 (noarch): jaxen-1.1.1-150000.5.3.1 jdom-1.1-150000.5.3.1 - SUSE Linux Enterprise Server for SAP 15 (noarch): jaxen-1.1.1-150000.5.3.1 jdom-1.1-150000.5.3.1 - SUSE Linux Enterprise Server 15-SP1-LTSS (noarch): jaxen-1.1.1-150000.5.3.1 jdom-1.1-150000.5.3.1 - SUSE Linux Enterprise Server 15-SP1-BCL (noarch): jaxen-1.1.1-150000.5.3.1 jdom-1.1-150000.5.3.1 - SUSE Linux Enterprise Server 15-LTSS (noarch): jaxen-1.1.1-150000.5.3.1 jdom-1.1-150000.5.3.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (noarch): jaxen-1.1.1-150000.5.3.1 jdom-1.1-150000.5.3.1 - SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS(noarch): jaxen-1.1.1-150000.5.3.1 jdom-1.1-150000.5.3.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (noarch): jaxen-1.1.1-150000.5.3.1 jdom-1.1-150000.5.3.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (noarch): jaxen-1.1.1-150000.5.3.1 jdom-1.1-150000.5.3.1 - SUSE Enterprise Storage 6 (noarch): jaxen-1.1.1-150000.5.3.1 jdom-1.1-150000.5.3.1 - SUSE CaaS Platform 4.0 (noarch): jaxen-1.1.1-150000.5.3.1 jdom-1.1-150000.5.3.1 References: https://www.suse.com/security/cve/CVE-2021-33813.html https://bugzilla.suse.com/1187446 . Recent patch for jdom tackles significant problems within SUSE setups, addressing potential denial of service threats.. SUSE Security, JDOM Update, Denial of Service Threat. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.