Updated java/timezone packages fix security vulnerability
Publication date: 07 Feb 2023Modification date: 06 Feb 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2023-21830 , CVE-2023-21835 , CVE-2023-21843
Description
Improper restrictions in CORBA deserialization. (CVE-2023-21830) Handshake DoS attack against DTLS connections. (CVE-2023-21835) Soundbank URL remote loading. (CVE-2023-21843)
References
- https://bugs.mageia.org/show_bug.cgi?id=31452
- https://access.redhat.com/errata/RHSA-2023:0203
- https://access.redhat.com/errata/RHSA-2023:0200
- https://www.oracle.com/security-alerts/cpujan2023.html#AppendixJAVA
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21830
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21835
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-21843
SRPMS
8/core
- java-1.8.0-openjdk-1.8.0.362.b09-1.mga8
- java-11-openjdk-11.0.18.0.10-1.mga8
- timezone-2022g-1.mga8