Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-129d8ca6fc 2024-03-07 22:24:39.963937 -------------------------------------------------------------------------------- Name : junit Product : Fedora 40 Version : 4.13.2 Release : 6.fc40 URL : https://junit.org/junit4/ Summary : Java regression test package Description : JUnit is a regression testing framework written by Erich Gamma and Kent Beck. It is used by the developer who implements unit tests in Java. JUnit is Open Source Software, released under the Common Public License Version 1.0 and hosted on GitHub. -------------------------------------------------------------------------------- Update Information: Change for system JDK from 17 to 21. upstream security release 122.0.6261.94 High CVE-2024-1938: Type Confusion in V8 High CVE-2024-1939: Type Confusion in V8 fixed bug with requires Automatic update for lucene-9.9.2-1.fc40. bump java source/target to 1.8, fixes 2266639 -------------------------------------------------------------------------------- ChangeLog: * Sat Mar 2 2024 Jiri Vanek - 1:4.13.2-6 - Rebuilt for java-21-openjdk as system jdk * Tue Feb 20 2024 Marian Koncek - 1:4.13.2-5 - Port to OpenJDK 21 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2123726 - consoleImageViewer crashes at start https://bugzilla.redhat.com/show_bug.cgi?id=2123726 [ 2 ] Bug #2261062 - directory-maven-plugin: FTBFS in Fedora rawhide/f40 https://bugzilla.redhat.com/show_bug.cgi?id=2261062 [ 3 ] Bug #2266639 - directory-maven-plugin fails to build with java-21-openjdk https://bugzilla.redhat.com/show_bug.cgi?id=2266639 [ 4 ] Bug #2266934 -CVE-2024-1938 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266934 [ 5 ] Bug #2266937 - CVE-2024-1939 chromium: type confusion [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2266937 [ 6 ] Bug #2267486 - Include Java 21 as system Java Change in Fedora 40 Beta https://bugzilla.redhat.com/show_bug.cgi?id=2267486 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-129d8ca6fc' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
It was discovered that junit contained a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by default, readable by other users on that same system. This vulnerability does not allow other users . MGASA-2020-0403 - Updated junit packages fix a security vulnerability Publication date: 08 Nov 2020 URL: https://advisories.mageia.org/MGASA-2020-0403.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-15250 It was discovered that junit contained a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by default, readable by other users on that same system. This vulnerability does not allow other usersto overwrite the contents of these directories or files. This is purely an information disclosure vulnerability (CVE-2020-15250). References: - https://bugs.mageia.org/show_bug.cgi?id=27555 - https://lists.debian.org/debian-lts-announce/2020/11/msg00003.html - https://github.com/junit-team/junit4/security/advisories/GHSA-269g-pwp5-87pp - https://www.cve.org/CVERecord?id=CVE-2020-15250 SRPMS: - 7/core/junit-4.12-7.1.mga7 . Mageia 2020-0405 resolves an internal data leakage vulnerability related to junit by providing upgraded packages to bolster security measures.. Local Information Disclosure, Mageia Security, Junit Update. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.