Lucene search

K
redhatRedHatRHSA-2022:7004
HistoryOct 19, 2022 - 9:05 p.m.

(RHSA-2022:7004) Moderate: java-1.8.0-openjdk security update

2022-10-1921:05:31
access.redhat.com
18
openjdk 8 java
security fix
x.509 certificate parsing
httpserver
ntlm client hostnames
jndi dns port.

0.002 Low

EPSS

Percentile

59.6%

The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.

Security Fix(es):

  • OpenJDK: excessive memory allocation in X.509 certificate parsing (Security, 8286533) (CVE-2022-21626)

  • OpenJDK: HttpServer no connection count limit (Lightweight HTTP Server, 8286918) (CVE-2022-21628)

  • OpenJDK: improper handling of long NTLM client hostnames (Security, 8286526) (CVE-2022-21619)

  • OpenJDK: insufficient randomization of JNDI DNS port numbers (JNDI, 8286910) (CVE-2022-21624)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.