Advisories ยป MGASA-2024-0319

Updated java-1.8.0-openjdk, java-11-openjdk, java-17-openjdk, & java-latest-openjdk packages fix security vulnerabilities

Publication date: 27 Sep 2024
Modification date: 27 Sep 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2024-21131 , CVE-2024-21138 , CVE-2024-21140 , CVE-2024-21144 , CVE-2024-21145 , CVE-2024-21147

Description

Potential UTF8 size overflow. (CVE-2024-21131)
Excessive symbol length can lead to infinite loop. (CVE-2024-21138)
Range Check Elimination (RCE) pre-loop limit overflow. (CVE-2024-21140)
Pack200 increase loading time due to improper header validation.
(CVE-2024-21144)
Out-of-bounds access in 2D image handling. (CVE-2024-21145)
RangeCheckElimination array index overflow. (CVE-2024-21147)
                

References

SRPMS

9/core