[CLSA-2023:1703610997] Fix of 5 CVEs
Type:
security
Severity:
Moderate
Release date:
2023-12-26 17:16:45 UTC
Description:
* Backport upstream releases 8u392 to 18.04 LTS * CVEs fixed in 8u392: - CVE-2023-22067: IOR deserialization issue in CORBA - CVE-2023-22081: Certificate path validation issue * CVEs fixed in 8u382: - CVE-2023-22045: OpenJDK incorrectly handled array accesses. - CVE-2023-22049: OpenJDK incorrectly sanitized URIs strings. * Drop applied CVE-2022-40433.patch (changes are already in the sources)
Updated packages:
  • openjdk-8-demo_8u392-ga~us1-0ubuntu1~18.04+tuxcare.els1_amd64.deb
    sha:4f310ca5d1b7f7e64bc84199ecb4561c98636b17
  • openjdk-8-doc_8u392-ga~us1-0ubuntu1~18.04+tuxcare.els1_all.deb
    sha:4e3f4940b9f029ee6c186edaecc50c6773d6cf99
  • openjdk-8-jdk_8u392-ga~us1-0ubuntu1~18.04+tuxcare.els1_amd64.deb
    sha:5714589159f8e5043939f5c112a258203ee54d0e
  • openjdk-8-jdk-headless_8u392-ga~us1-0ubuntu1~18.04+tuxcare.els1_amd64.deb
    sha:b77be1f5f7a877939cfc4776252ad03eb88adb34
  • openjdk-8-jre_8u392-ga~us1-0ubuntu1~18.04+tuxcare.els1_amd64.deb
    sha:1ad44754117280195d3ec621d4eb29b3ace4ed09
  • openjdk-8-jre-headless_8u392-ga~us1-0ubuntu1~18.04+tuxcare.els1_amd64.deb
    sha:9ffa9e12ab76715fa69ec984022153608cefec0b
  • openjdk-8-jre-zero_8u392-ga~us1-0ubuntu1~18.04+tuxcare.els1_amd64.deb
    sha:f566038176a22ded2e9ae19039dad21faa33fc6d
  • openjdk-8-source_8u392-ga~us1-0ubuntu1~18.04+tuxcare.els1_all.deb
    sha:3719b9af22ccd670cafb37d5883823b8f58a9d4d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.