MGASA-2023-0272

Source
https://advisories.mageia.org/MGASA-2023-0272.html
Import Source
https://advisories.mageia.org/MGASA-2023-0272.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2023-0272
Related
Published
2023-09-30T19:15:40Z
Modified
2023-09-30T17:30:59Z
Summary
Updated java packages fix security vulnerabilities
Details

The updated packages fix security vulnerabilities and a file conflict :

Improper connection handling during TLS handshake. (CVE-2023-21930)

Incorrect enqueue of references in garbage collector. (CVE-2023-21954)

Certificate validation issue in TLS session negotiation. (CVE-2023-21967)

Swing HTML parsing issue. (CVE-2023-21939)

Incorrect handling of NULL characters in ProcessBuilder. (CVE-2023-21938)

Missing string checks for NULL characters. (CVE-2023-21937)

Missing check for slash characters in URI-to-path conversion. (CVE-2023-21968)

Array indexing integer overflow issue. (CVE-2023-22045)

Improper handling of slash characters in URI-to-path conversion. (CVE-2023-22049)

O(n^2) growth via consecutive marks. (CVE-2023-25193)

HTTP client insufficient file name validation. (CVE-2023-22006)

ZIP file parsing infinite loop. (CVE-2023-22036)

Modulo operator array indexing issue. (CVE-2023-22044)

Weakness in AES implementation. (CVE-2023-22041)

References
Credits

Affected packages

Mageia:9 / java-1.8.0-openjdk

Package

Name
java-1.8.0-openjdk
Purl
pkg:rpm/mageia/java-1.8.0-openjdk?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.0.382.b05-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / java-11-openjdk

Package

Name
java-11-openjdk
Purl
pkg:rpm/mageia/java-11-openjdk?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.0.20.0.8-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / java-17-openjdk

Package

Name
java-17-openjdk
Purl
pkg:rpm/mageia/java-17-openjdk?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
17.0.8.0.7-1.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:9 / java-latest-openjdk

Package

Name
java-latest-openjdk
Purl
pkg:rpm/mageia/java-latest-openjdk?distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
20.0.2.0.9-1.rolling.2.mga9

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / java-1.8.0-openjdk

Package

Name
java-1.8.0-openjdk
Purl
pkg:rpm/mageia/java-1.8.0-openjdk?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.0.382.b05-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / java-11-openjdk

Package

Name
java-11-openjdk
Purl
pkg:rpm/mageia/java-11-openjdk?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.0.20.0.8-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / openjfx

Package

Name
openjfx
Purl
pkg:rpm/mageia/openjfx?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
11.0.9.2-4.mga8

Ecosystem specific

{
    "section": "core"
}