java-1.7.0-openjdk-1.7.0.231-2.6.19.1.AXS4

エラータID: AXSA:2019-3940:03

Release date: 
Tuesday, July 23, 2019 - 21:24
Subject: 
java-1.7.0-openjdk-1.7.0.231-2.6.19.1.AXS4
Affected Channels: 
Asianux Server 4 for x86_64
Asianux Server 4 for x86
Severity: 
Moderate
Description: 

The java-1.7.0-openjdk packages provide the OpenJDK 7 Java Runtime Environment and the OpenJDK 7 Java Software Development Kit.

Security Fix(es):

* OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745)

* OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762)

* OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769)

* OpenJDK: Missing URL format validation (Networking, 8221518) (CVE-2019-2816)

* OpenJDK: Missing array bounds check in crypto providers (JCE, 8223511) (CVE-2019-2842)

* OpenJDK: Insufficient restriction of privileges in AccessController (Security, 8216381) (CVE-2019-2786)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2019-2745
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-2762
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-2769
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-2786
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-2816
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
CVE-2019-2842
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. java-1.7.0-openjdk-1.7.0.231-2.6.19.1.AXS4.src.rpm
    MD5: 0d0f61cb648c6c1b576c6921f949ba04
    SHA-256: 253531d78ec85a87ef1685873baa0a91676877bbcbc1973892b5b8023c0ddcb6
    Size: 39.73 MB

Asianux Server 4 for x86
  1. java-1.7.0-openjdk-1.7.0.231-2.6.19.1.AXS4.i686.rpm
    MD5: d8abfbd0b9b3f5af7f90b05d0e6b2119
    SHA-256: a4f7158163731a55303d80d1d73eba2a1bdcf4f9ea282665e3a4f95eb5f7e7be
    Size: 27.84 MB
  2. java-1.7.0-openjdk-devel-1.7.0.231-2.6.19.1.AXS4.i686.rpm
    MD5: e6cf1a975f83c59b085a650a51166956
    SHA-256: 90507d19f5c00dfa30b7f478c6e734cce026ce6972d506c58bd70ae818135094
    Size: 9.49 MB

Asianux Server 4 for x86_64
  1. java-1.7.0-openjdk-1.7.0.231-2.6.19.1.AXS4.x86_64.rpm
    MD5: 069b2796be1eaa6c510ddc670cec0c3e
    SHA-256: 08c5425f3822be08e1bc866c108662898f8a3b62da6a6b0d2c46f715a4047d68
    Size: 26.60 MB
  2. java-1.7.0-openjdk-devel-1.7.0.231-2.6.19.1.AXS4.x86_64.rpm
    MD5: 9cef5f2d06f46dc3745082045ff55009
    SHA-256: 7e9cbaa462788a7986651b994351179c34228ac9e9459d44c4047de2b0b6be85
    Size: 9.49 MB