RHSA-2024:0223 Redhat java-1.8.0-openjdkID: oval:org.secpod.oval:def:97884 | Date: (C)2024-02-09 (M)2024-04-25 |
Class: PATCH | Family: unix |
The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. Security Fix: OpenJDK: array out-of-bounds access due to missing range check in C1 compiler OpenJDK: RSA padding issue and timing side-channel attack against TLS OpenJDK: JVM class file verifier flaw allows unverified bytecode execution OpenJDK: range check loop optimization issue OpenJDK: arbitrary Java code execution in Nashorn OpenJDK: logging of digital signature private keys For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Bug Fix: In the previous release in October 2023 , the RPMs were changed to use Provides for java, jre, java-headless, jre-headless, java-devel and java-sdk which included the full RPM version. This prevented the Provides being used to resolve a dependency on Java 1.8.0 . This change has now been reverted to the old "1:1.8.0" value
Platform: |
Red Hat Enterprise Linux 7 |
Product: |
java-1.8.0-openjdk |