Happy Friday fellow Linux geeks! This week, important updates have been issued for Firefox, OpenJDK and the Linux Kernel. Read on to learn about these vulnerabilities and how to secure your system against them. 

Have a question about or comment on one of the vulnerabilities highlighted in today's newsletter? Let's discuss!

Check out the new Remote Access Plus solution from ManageEngine to help admins secure their servers against vulnerabilities like these by automating security patches.

Yours in Open Source,

Brittany Signature 150

 

Firefox

The Discovery 

Multiple security vulnerabilities were discovered in Mozilla Firefox (CVE-2022-42927, CVE-2022-42928, CVE-2022-42929 and CVE-2022-42932).

Firefox

The Impact

These issues could result in the leakage of cross-origin URLs, memory corruption and denial of service (DoS).

The Fix

An important Firefox security update that mitigates these dangerous flaws has been released. We recommend that you update now to protect the security, integrity and availability of your systems.

Your Related Advisories:

Register to Customize Your Advisories

OpenJDK

The Discovery 

Several security bugs have been found in OpenJDK (CVE-2022-21626, CVE-2022-21628, CVE-2022-21619 and CVE-2022-21624).


Openjdk

The Impact

These flaws could result in excessive memory allocation in X.509 certificate parsing, no connection count limit in HttpServer, improper handling of long NTLM client hostnames and insufficient randomization of JNDI DNS port numbers.

The Fix

A java-1.8.0-openjdk security and bug fix update that remedies these issues is now available. We recommend that you update as soon as possible to protect against potential attacks and compromise due to the exploitation of these vulnerabilities.

Your Related Advisories:

Register to Customize Your Advisories

Linux Kernel

The Discovery

Several security issues were identified in the Linux kernel (CVE-2022-0812, CVE-2022-1012, CVE-2022-2318, CVE-2022-26365, CVE-2022-32296, CVE-2022-33740, CVE-2022-33741, CVE-2022-33742 and CVE-2022-33744).

The Impact

These bugs could result in the exposure of sensitive information or denial of service (DoS) attacks.

LinuxKernel

The Fix

An update for the Linux kernel that fixes these vulnerabilities has been released. We recommend that you update immediately to prevent disruptive downtime and protect the privacy of your sensitive information.

Your Related Advisories:

Register to Customize Your Advisories