Advisories ยป MGASA-2022-0435

Updated java packages fix security vulnerability

Publication date: 24 Nov 2022
Modification date: 24 Nov 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-21540 , CVE-2022-21541 , CVE-2022-21618 , CVE-2022-21619 , CVE-2022-21624 , CVE-2022-21626 , CVE-2022-21628 , CVE-2022-34169 , CVE-2022-39399

Description

Class compilation issue. (CVE-2022-21540)
Improper restriction of MethodHandle.invokeBasic(). (CVE-2022-21541)
Integer truncation issue in Xalan-J. (CVE-2022-34169)
Improper MultiByte conversion can lead to buffer overflow. (CVE-2022-21618)
Improper handling of long NTLM client hostnames. (CVE-2022-21619)
Insufficient randomization of JNDI DNS port numbers. (CVE-2022-21624)
Excessive memory allocation in X.509 certificate parsing. (CVE-2022-21626)
HttpServer no connection count limit. (CVE-2022-21628)
Missing SNI caching in HTTP/2. (CVE-2022-39399)
                

References

SRPMS

8/core