Advisories ยป MGASA-2024-0364

Updated java-1.8.0-openjdk, java-11-openjdk, java-17-openjdk, java-21-openjdk & java-latest-openjdk packages fix security vulnerabilities

Publication date: 13 Nov 2024
Modification date: 13 Nov 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-48161 , CVE-2024-21208 , CVE-2024-21210 , CVE-2024-21217 , CVE-2024-21235

Description

giflib: Heap-Buffer Overflow during Image Saving in DumpScreen2RGB
Function. (CVE-2023-48161)
Array indexing integer overflow. (CVE-2024-21210)
HTTP client improper handling of maxHeaderSize. (CVE-2024-21208)
Unbounded allocation leads to out-of-memory error. (CVE-2024-21217)
Integer conversion error leads to incorrect range check.
(CVE-2024-21235)
                

References

SRPMS

9/core