java-1.8.0-openjdk-1.8.0.342.b07-2.el8

エラータID: AXSA:2022-3696:07

Release date: 
Tuesday, August 16, 2022 - 04:19
Subject: 
java-1.8.0-openjdk-1.8.0.342.b07-2.el8
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.

The following packages have been upgraded to a later upstream version: java-1.8.0-openjdk (1.8.0.342.b07).

Security Fix(es):

* OpenJDK: integer truncation issue in Xalan-J (JAXP, 8285407) (CVE-2022-34169)
* OpenJDK: class compilation issue (Hotspot, 8281859) (CVE-2022-21540)
* OpenJDK: improper restriction of MethodHandle.invokeBasic() (Hotspot, 8281866) (CVE-2022-21541)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

* rh1991003 patch breaks sun.security.pkcs11.wrapper.PKCS11.getInstance() [openjdk-8]
* Revert to disabling system security properties and FIPS mode support together [openjdk-8]
* SecretKey generate/import operations don't add the CKA_SIGN attribute in FIPS mode [openjdk-8]

CVE-2022-21540
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
CVE-2022-21541
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.1 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
CVE-2022-34169
The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execute arbitrary Java bytecode. The Apache Xalan Java project is dormant and in the process of being retired. No future releases of Apache Xalan Java to address this issue are expected. Note: Java runtimes (such as OpenJDK) include repackaged copies of Xalan.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. java-1.8.0-openjdk-1.8.0.342.b07-2.el8.src.rpm
    MD5: eb4cb8605b6e2360c5951f72ecbff4db
    SHA-256: d17032d384c401f20e1e10d967bee99e1fd87066dfd879b771dcbbc027d7f5c8
    Size: 55.75 MB

Asianux Server 8 for x86_64
  1. java-1.8.0-openjdk-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: 30b9c2f089b4368cf8f0f54733693a89
    SHA-256: 11379f932f75568ad2a6ad1eca954e1e34126351616389a3e9d1555c5cadc6da
    Size: 347.02 kB
  2. java-1.8.0-openjdk-accessibility-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: e20d6361c63aba58cdfb368cb5055420
    SHA-256: f1012b4e391fd81e931f45ecd8f20161c470cba19de4aeb7dfd0805d6f84b43d
    Size: 109.63 kB
  3. java-1.8.0-openjdk-accessibility-fastdebug-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: 213beaeaebac479436c33ed742b3baeb
    SHA-256: de2d2586b5887390b5dc092ce886465c4624107547e76c257edd7035628903ef
    Size: 109.48 kB
  4. java-1.8.0-openjdk-accessibility-slowdebug-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: 022ee9ce3e9f589a3912c64331f97b81
    SHA-256: 89b5aee7564f437d182a7e2fad18cff20d0b4275a6d05a380821accc5f57f3d7
    Size: 109.48 kB
  5. java-1.8.0-openjdk-demo-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: de518fb4bbca04abfbfa05fddcb49c7c
    SHA-256: 56b1288b24434cb8b67ed47c2f50a94d2912a907d95beb46754be405a08b39ba
    Size: 2.02 MB
  6. java-1.8.0-openjdk-demo-fastdebug-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: 59f7d9048579bb89969ab5332e607bd9
    SHA-256: 19b6879b9d7f4cc54cb4d7cd5d72df80a6066a12b5595e7289cc1fbf3abf9fe0
    Size: 2.04 MB
  7. java-1.8.0-openjdk-demo-slowdebug-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: 1cf59d23367ac97b7de31f454fd2a87f
    SHA-256: ffc6223514f44878416a8b8a98fb0812c91e56850f3796dbb3ad5a15abce482f
    Size: 2.04 MB
  8. java-1.8.0-openjdk-devel-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: 35fec4b814f5a926b476b3198f7ff105
    SHA-256: 3e8b166731f3b6ef64edd4ee138e0320e78e6b9d5afc3d91d26e2df009ad1176
    Size: 9.88 MB
  9. java-1.8.0-openjdk-devel-fastdebug-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: 715552878d87c9b9987f70696f39603c
    SHA-256: ffbecceed5eb34c13bc5f99f210509299d770a6a39758d8adee813fa04c1371e
    Size: 9.89 MB
  10. java-1.8.0-openjdk-devel-slowdebug-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: 1f71281638084984270b358c71c0ec76
    SHA-256: f70f65ce6e329d2ede4dc2f4e715b8016986e6bd2d985ef52599df67cdc663c8
    Size: 9.90 MB
  11. java-1.8.0-openjdk-fastdebug-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: 90c7d188d14bc82113aa636319d81805
    SHA-256: ed8e2ec83de2f3db117a333a92b68a40942bc8e51ae57413771f2b2e6241e33f
    Size: 360.38 kB
  12. java-1.8.0-openjdk-headless-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: 1bafcdea60ee4dcc7e107107972ad54b
    SHA-256: c91243bcadf4459371e0f86872117fe1bcf26940ccf0b071d14cce7a9c04d1af
    Size: 33.96 MB
  13. java-1.8.0-openjdk-headless-fastdebug-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: 0e32b3286bf48413a9569afca6c33197
    SHA-256: 584ba2b364e5e2f8fab7e313c6d8a4f6cb48d4dc32ed1bf752e41c08225148b1
    Size: 37.62 MB
  14. java-1.8.0-openjdk-headless-slowdebug-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: f242dc3a628ef91c568557fa35788d04
    SHA-256: db7bdf9be3023c4bcd778b5d89f24f1b7a0ed349dd94563149ca454531816fbb
    Size: 35.78 MB
  15. java-1.8.0-openjdk-javadoc-1.8.0.342.b07-2.el8.noarch.rpm
    MD5: 16c398fd91e3a4e1f5fb8cb10df3d43c
    SHA-256: f766341f83d7dda69a759bc69162e8b254494a38a397cc439ddf6a4179701141
    Size: 15.18 MB
  16. java-1.8.0-openjdk-javadoc-zip-1.8.0.342.b07-2.el8.noarch.rpm
    MD5: fe617cad8dbfb8afed7151502acbac4c
    SHA-256: 7db6cdef60019cd04964744455dfb7ba037e5c6eed9b0228d4b81068fbf3322e
    Size: 41.69 MB
  17. java-1.8.0-openjdk-slowdebug-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: 4b2c8efd5c2e6ad6d8aac5731119f4fd
    SHA-256: f4f8665621f64651e7f9f938397a6d36d4c206fc79718d5569d249134add5753
    Size: 351.29 kB
  18. java-1.8.0-openjdk-src-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: 9721f0e2cd8b36fd2b475a40ef8365ef
    SHA-256: b0806f25106ead26552bb9fc238e497bb1ddfa45e51863db6953d37f9027418d
    Size: 45.46 MB
  19. java-1.8.0-openjdk-src-fastdebug-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: ae82eb95ac5168791184e75bd773eb40
    SHA-256: fea8486c484cb0597d7f749e1801bee6b78114de196bd214a6f9720600f52b72
    Size: 45.46 MB
  20. java-1.8.0-openjdk-src-slowdebug-1.8.0.342.b07-2.el8.x86_64.rpm
    MD5: a23bf0e67414fc04c79fd258e4c0f61b
    SHA-256: 62ebe7f1496f35ae0002bdb142b7b779f03b95d4b624cc384868943cab43fbc9
    Size: 45.46 MB