java-1.8.0-openjdk-1.8.0.222.b10-0.el7

エラータID: AXSA:2019-3939:04

Release date: 
Tuesday, July 23, 2019 - 03:58
Subject: 
java-1.8.0-openjdk-1.8.0.222.b10-0.el7
Affected Channels: 
Asianux Server 7 for x86_64
Severity: 
Moderate
Description: 

The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.

Security Fix(es):

* OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745)

* OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762)

* OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769)

* OpenJDK: Missing URL format validation (Networking, 8221518) (CVE-2019-2816)

* OpenJDK: Missing array bounds check in crypto providers (JCE, 8223511) (CVE-2019-2842)

* OpenJDK: Insufficient restriction of privileges in AccessController (Security, 8216381) (CVE-2019-2786)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2019-2745
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-2762
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-2769
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-2786
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-2816
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-2842
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. java-1.8.0-openjdk-1.8.0.222.b10-0.el7.src.rpm
    MD5: 04e56eaa995a030e6095d1a270513914
    SHA-256: 9e33dba6508c91d37221f2d6ea557de56e833e8cc49cd3c09e0f7fc06cb002c3
    Size: 53.98 MB

Asianux Server 7 for x86_64
  1. java-1.8.0-openjdk-1.8.0.222.b10-0.el7.x86_64.rpm
    MD5: cb60d08603fdbb528f30393a385afc5f
    SHA-256: d011c920adffd8c65c4ba50cbe08cf5d2b0b1d0aa43e106f498ab9af353f3a86
    Size: 272.89 kB
  2. java-1.8.0-openjdk-devel-1.8.0.222.b10-0.el7.x86_64.rpm
    MD5: 68535dc58a04058b0c72d22c13096b12
    SHA-256: d71e42af6f71e17ebd4f27e364d18684e63601158526ca548c3887ad5b6c9354
    Size: 9.81 MB
  3. java-1.8.0-openjdk-headless-1.8.0.222.b10-0.el7.x86_64.rpm
    MD5: 8f2e9ee1a9772371e530aaa398234ca1
    SHA-256: 6d63f728dbe62ef7a4b4b2babfa631c4dd147109c09ebaadd92d3a95ac0910d1
    Size: 31.81 MB