The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available for Windows. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: OpenJDK 8u302 Windows Builds release and security update Advisory ID: RHSA-2021:2777-01 Product: OpenJDK Advisory URL: https://access.redhat.com/errata/RHSA-2021:2777 Issue date: 2021-07-22 Keywords: openjdk,windows CVE Names: CVE-2021-2341 CVE-2021-2369 CVE-2021-2388 ==================================================================== 1. Summary: The Red Hat Build of OpenJDK 8 (java-1.8.0-openjdk) is now available for Windows. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. This release of the Red Hat build of OpenJDK 8 (1.8.0.302) for Windows serves as a replacement for the Red Hat build of OpenJDK 8 (1.8.0.292) and includes security and bug fixes, and enhancements. For further information, refer to the release notes linked to in the References section. Security Fix(es): * OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) (CVE-2021-2341) * OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) (CVE-2021-2369) * OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066) (CVE-2021-2388) For more details about the security issue(s), including the impact, a CVSS score,acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: _using_openjdk_8_for_windows/index 4. Bugs fixed (https://bugzilla.redhat.com/): 1982874 - CVE-2021-2341 OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) 1982879 - CVE-2021-2369 OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) 1983075 - CVE-2021-2388 OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066) 5. References: https://access.redhat.com/security/cve/CVE-2021-2341 https://access.redhat.com/security/cve/CVE-2021-2369 https://access.redhat.com/security/cve/CVE-2021-2388 https://access.redhat.com/security/updates/classification/#important 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYPmI4tzjgjWX9erEAQjpDA//XKpw/yHHfR14STaEwgza2ehIgxh+RJai NaHv/3lJKfyKn6CNv4cDGtJ07rDoCn5QbZsdlXm6Gjhh0OyCXjcLO0zKQKb9uhfH 6/6lwMArEbBlVUhycaEyDUBRgw6cO2W54PEYBsD0JYCcKbDdxJ/RAzuYgd26Qid+ kXl3PO1+erpwBVCsKhDgVh+ei0xfpOgROd8fDvCEEG0cC6wbE3rI/RVxnge5gfoH 5SDNzeXSx2X68eFeiGQr/IB95kO9OioOZyF2Edk8Oi9KJ/Tzg1VLBVVcvrJRplHZ xp6pk3WupncRI4QNEC/Y4NebMdZROUOKvPJDZ6DcEem2ekgErkFKZpIuKssZsGjK LJR/RKATGfnzUbjN0N7ZPFtTFQjpKZOFuC9bet4q/Iq2GSFFIAmKUZzoOLfnCC3C Sdxj3os9+Q0t1yHn1Q6JwT9bnfEplFu90dOgHYasmaIEUDrZv0Ify4eWRbkjiYL6 kJraJXCDReDbPnBAKF8yUD+2Jrlb+j7R27L2B8N02nCqcSkVQ7WTqURf8V5tmkUT YZ+8S4Ag1BDOc59zlUq16vMwhCE/IBzhab8Dz5RCUqEQ2n8BMTmbxcFkxjd88Ed8 J5ChUbIdwTHYOYvBCvL6lC801xlSfz34DmkT3PsmF5QltdeBOr8Y9pIGL/9KaXhd /lIDnLduSus=5Nwu -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Fixes CVE-2017-9502 (Windows builds only). --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-03fc914348 2017-06-21 02:34:45.387464 --------------------------------------------------------------------------------Name : mingw-curl Product : Fedora 26 Version : 7.54.1 Release : 1.fc26 URL : https://curl.se/ Summary : MinGW Windows port of curl and libcurl Description : cURL is a tool for getting files from HTTP, FTP, FILE, LDAP, LDAPS, DICT, TELNET and TFTP servers, using any of the supported protocols. cURL is designed to work without user interaction or any kind of interactivity. cURL offers many useful capabilities, like proxy support, user authentication, FTP upload, HTTP post, and file transfer resume. This is the MinGW cross-compiled Windows library. --------------------------------------------------------------------------------Update Information: Fixes CVE-2017-9502 (Windows builds only) --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mingw-curl' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.