Lucene search

K
mageiaGentoo FoundationMGASA-2020-0309
HistoryAug 01, 2020 - 2:25 a.m.

Updated java-1.8.0-openjdk packages fix security vulnerability

2020-08-0102:25:42
Gentoo Foundation
advisories.mageia.org
37
java security vulnerability
buffer bypass
affine transformations
access control context
derinputstream
dervalue.equals()
xml validation manipulation
hostnamechecker
unix
cve-2020-14583
cve-2020-14593
cve-2020-14556
cve-2020-14578
cve-2020-14579
cve-2020-14621
cve-2020-14577

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

8.3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS

0.003

Percentile

71.8%

Bypass of boundary checks in nio.Buffer via concurrent access. (CVE-2020-14583) Incomplete bounds checks in Affine Transformations. (CVE-2020-14593) Incorrect handling of access control context in ForkJoinPool. (CVE-2020-14556) Unexpected exception raised by DerInputStream. (CVE-2020-14578) Unexpected exception raised by DerValue.equals(). (CVE-2020-14579) XML validation manipulation due to incomplete application of the use-grammar-pool-only feature. (CVE-2020-14621) HostnameChecker does not ensure X.509 certificate names are in normalized form. (CVE-2020-14577)

OSVersionArchitecturePackageVersionFilename
Mageia7noarchjava< 1.8.0-openjdk-1.8.0.262-1.b10.1java-1.8.0-openjdk-1.8.0.262-1.b10.1.mga7

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

8.3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

EPSS

0.003

Percentile

71.8%