[CLSA-2022:1669309108] Fix CVE(s): CVE-2022-21628, CVE-2022-21626, CVE-2022-21624, CVE-2022-21619
Type:
security
Severity:
Moderate
Release date:
2022-11-24 16:58:28 UTC
Description:
* Backport upstream releases 8u352 to 16.04 LTS * Security fixes in 8u352: - JDK-8282252: Improve BigInteger/Decimal validation - JDK-8285662: Better permission resolution - JDK-8286511: Improve macro allocation - JDK-8286519: Better memory handling - JDK-8286526, CVE-2022-21619: Improve NTLM support - JDK-8286533, CVE-2022-21626: Key X509 usages - JDK-8286910, CVE-2022-21624: Improve JNDI lookups - JDK-8286918, CVE-2022-21628: Better HttpServer service - JDK-8288508: Enhance ECDSA usage * Drop applied patch pr88.diff
Updated packages:
  • openjdk-8-demo_8u352-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:28b0f9df016bc594463851dc78efcab30969b53d
  • openjdk-8-doc_8u352-ga-0ubuntu1~16.04+tuxcare.els1_all.deb
    sha:7164fec1d4f90b62c420af91debb6615386a332e
  • openjdk-8-jdk_8u352-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:ea89e5de5f447b36e2f5ecb5d3b053560ee7581a
  • openjdk-8-jdk-headless_8u352-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:2b7eea79414897a3496055702670b3064441fa94
  • openjdk-8-jre_8u352-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:f9b234d7ac8bafc6b73e153d6a5108cfbd2ee6ae
  • openjdk-8-jre-headless_8u352-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:a308d61742a3ab671adae14a0e7d645ba12629c7
  • openjdk-8-jre-jamvm_8u352-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:b79f66b34ed5c545ebfe5e2fe833ccdf3386086a
  • openjdk-8-jre-zero_8u352-ga-0ubuntu1~16.04+tuxcare.els1_amd64.deb
    sha:b670944a6534006496f78784ad3f8bf32c5938c6
  • openjdk-8-source_8u352-ga-0ubuntu1~16.04+tuxcare.els1_all.deb
    sha:6eb0e07920d358e91f11ad02ea8272627e5f0543
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.