Synopsis:          Moderate: java-1.8.0-openjdk security and bug fix update
Advisory ID:       SLSA-2020:4350-1
Issue Date:        2020-10-27
CVE Numbers:       None
--

Security Fix(es):

* OpenJDK: Credentials sent over unencrypted LDAP connection (JNDI,
8237990) (CVE-2020-14781)

* OpenJDK: Certificate blacklist bypass via alternate certificate encodings
(Libraries, 8237995) (CVE-2020-14782)

* OpenJDK: Integer overflow leading to out-of-bounds access (Hotspot,
8241114) (CVE-2020-14792)

* OpenJDK: Incomplete check for invalid characters in URI to path
conversion (Libraries, 8242685) (CVE-2020-14797)

* OpenJDK: Race condition in NIO Buffer boundary checks (Libraries,
8244136) (CVE-2020-14803)

* OpenJDK: High memory usage during deserialization of Proxy class with
many interfaces (Serialization, 8236862) (CVE-2020-14779)

* OpenJDK: Missing permission check in path to URI conversion (Libraries,
8242680) (CVE-2020-14796)
--

SL7
  x86_64
    java-1.8.0-openjdk-1.8.0.272.b10-1.el7_9.i686.rpm
    java-1.8.0-openjdk-1.8.0.272.b10-1.el7_9.x86_64.rpm
    java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-1.el7_9.i686.rpm
    java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-1.el7_9.x86_64.rpm
    java-1.8.0-openjdk-headless-1.8.0.272.b10-1.el7_9.i686.rpm
    java-1.8.0-openjdk-headless-1.8.0.272.b10-1.el7_9.x86_64.rpm
    java-1.8.0-openjdk-accessibility-1.8.0.272.b10-1.el7_9.i686.rpm
    java-1.8.0-openjdk-accessibility-1.8.0.272.b10-1.el7_9.x86_64.rpm
    java-1.8.0-openjdk-demo-1.8.0.272.b10-1.el7_9.i686.rpm
    java-1.8.0-openjdk-demo-1.8.0.272.b10-1.el7_9.x86_64.rpm
    java-1.8.0-openjdk-devel-1.8.0.272.b10-1.el7_9.i686.rpm
    java-1.8.0-openjdk-devel-1.8.0.272.b10-1.el7_9.x86_64.rpm
    java-1.8.0-openjdk-src-1.8.0.272.b10-1.el7_9.i686.rpm
    java-1.8.0-openjdk-src-1.8.0.272.b10-1.el7_9.x86_64.rpm
  noarch
    java-1.8.0-openjdk-javadoc-1.8.0.272.b10-1.el7_9.noarch.rpm
    java-1.8.0-openjdk-javadoc-zip-1.8.0.272.b10-1.el7_9.noarch.rpm

- Scientific Linux Development Team

SciLinux: SLSA-2020-4350-1 Moderate: java-1.8.0-openjdk on SL7.x x86_64

OpenJDK: Credentials sent over unencrypted LDAP connection (JNDI, 8237990) (CVE-2020-14781) * OpenJDK: Certificate blacklist bypass via alternate certificate encodings (Libraries, ...

Summary

Moderate: java-1.8.0-openjdk security and bug fix update



Security Fixes

* OpenJDK: Credentials sent over unencrypted LDAP connection (JNDI, 8237990) (CVE-2020-14781)
* OpenJDK: Certificate blacklist bypass via alternate certificate encodings (Libraries, 8237995) (CVE-2020-14782)
* OpenJDK: Integer overflow leading to out-of-bounds access (Hotspot, 8241114) (CVE-2020-14792)
* OpenJDK: Incomplete check for invalid characters in URI to path conversion (Libraries, 8242685) (CVE-2020-14797)
* OpenJDK: Race condition in NIO Buffer boundary checks (Libraries, 8244136) (CVE-2020-14803)
* OpenJDK: High memory usage during deserialization of Proxy class with many interfaces (Serialization, 8236862) (CVE-2020-14779)
* OpenJDK: Missing permission check in path to URI conversion (Libraries, 8242680) (CVE-2020-14796)
SL7 x86_64 java-1.8.0-openjdk-1.8.0.272.b10-1.el7_9.i686.rpm java-1.8.0-openjdk-1.8.0.272.b10-1.el7_9.x86_64.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-1.el7_9.i686.rpm java-1.8.0-openjdk-debuginfo-1.8.0.272.b10-1.el7_9.x86_64.rpm java-1.8.0-openjdk-headless-1.8.0.272.b10-1.el7_9.i686.rpm java-1.8.0-openjdk-headless-1.8.0.272.b10-1.el7_9.x86_64.rpm java-1.8.0-openjdk-accessibility-1.8.0.272.b10-1.el7_9.i686.rpm java-1.8.0-openjdk-accessibility-1.8.0.272.b10-1.el7_9.x86_64.rpm java-1.8.0-openjdk-demo-1.8.0.272.b10-1.el7_9.i686.rpm java-1.8.0-openjdk-demo-1.8.0.272.b10-1.el7_9.x86_64.rpm java-1.8.0-openjdk-devel-1.8.0.272.b10-1.el7_9.i686.rpm java-1.8.0-openjdk-devel-1.8.0.272.b10-1.el7_9.x86_64.rpm java-1.8.0-openjdk-src-1.8.0.272.b10-1.el7_9.i686.rpm java-1.8.0-openjdk-src-1.8.0.272.b10-1.el7_9.x86_64.rpm noarch java-1.8.0-openjdk-javadoc-1.8.0.272.b10-1.el7_9.noarch.rpm java-1.8.0-openjdk-javadoc-zip-1.8.0.272.b10-1.el7_9.noarch.rpm
- Scientific Linux Development Team

Severity
Advisory ID: SLSA-2020:4350-1
Issued Date: : 2020-10-27
CVE Numbers: None

Related News