2020年8月9日 星期日

[USN-4453-1] OpenJDK 8 vulnerabilities

 ---------- Forwarded message ---------

From: Eduardo Barretto <eduardo.barretto@canonical.com>

Date: Aug 6, 2020 2:36AM


Johannes Kuhn discovered that OpenJDK 8 incorrectly handled access control

contexts. An attacker could possibly use this issue to execute arbitrary

code. (CVE-2020-14556)


Philippe Arteau discovered that OpenJDK 8 incorrectly verified names in

TLS server's X.509 certificates. An attacker could possibly use this

issue to obtain sensitive information. (CVE-2020-14577)


It was discovered that OpenJDK 8 incorrectly handled exceptions in

DerInputStream class and in the DerValue.equals() method. An attacker

could possibly use this issue to cause a denial of service.

(CVE-2020-14578, CVE-2020-14579)


It was discovered that OpenJDK 8 incorrectly handled image files. An

attacker could possibly use this issue to obtain sensitive information.

(CVE-2020-14581)


Markus Loewe discovered that OpenJDK 8 incorrectly handled concurrent

access in java.nio.Buffer class. An attacker could use this issue to

bypass sandbox restrictions.

(CVE-2020-14583)


It was discovered that OpenJDK 8 incorrectly handled transformation of

images. An attacker could possibly use this issue to bypass sandbox

restrictions and insert, edit or obtain sensitive information.

(CVE-2020-14593)


Roman Shemyakin discovered that OpenJDK 8 incorrectly handled XML files.

An attacker could possibly use this issue to insert, edit or obtain

sensitive information. (CVE-2020-14621)


References:

  https://usn.ubuntu.com/4453-1

  CVE-2020-14556, CVE-2020-14577, CVE-2020-14578, CVE-2020-14579,

  CVE-2020-14581, CVE-2020-14583, CVE-2020-14593, CVE-2020-14621

沒有留言:

張貼留言