Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- Gentoo Linux Security Advisory 202401-25[6]
- Authored by Gentoo[7] | Site security.gentoo.org[8]
-
Gentoo Linux Security Advisory 202401-25 - Multiple vulnerabilities have been discovered in OpenJDK, the worst of which can lead to remote code execution. Versions greater than or equal to 11.0.19_p7:11 are affected.
- systems | linux[9], gentoo[10]
- advisories | CVE-2022-21540[11], CVE-2022-21541[12], CVE-2022-21549[13], CVE-2022-21618[14], CVE-2022-21619[15], CVE-2022-21624[16], CVE-2022-21626[17], CVE-2022-21628[18], CVE-2022-34169[19], CVE-2022-39399[20], CVE-2022-42920[21], CVE-2023-21830[22], CVE-2023-21835[23], CVE-2023-21843[24]
- SHA-256 |
0a4fe242d77ea01ee2a725ae008fbefb532aeaf7181a2f1427c642180897d42f - Download[25] | Favorite[26] | View[27]
Change Mirror[28] Download[29]
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202401-25
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: OpenJDK: Multiple Vulnerabilities
Date: January 17, 2024
Bugs: #859376, #859400, #877597, #891323, #908243
ID: 202401-25
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Multiple vulnerabilities have been discovered in OpenJDK, the worst of
which can lead to remote code execution.
Background
==========
OpenJDK is an open source implementation of the Java programming
language.
Affected packages
=================
Package Vulnerable Unaffected
------------------------ --------------- ----------------
dev-java/openjdk < 11.0.19_p7:11 >= 11.0.19_p7:11
< 17.0.7_p7:17 >= 17.0.7_p7:17
< 8.372_p07:8 >= 8.372_p07:8
dev-java/openjdk-bin < 11.0.19_p7:11 >= 11.0.19_p7:11
< 17.0.7_p7:17 >= 17.0.7_p7:17
< 8.372_p07:8 >= 8.372_p07:8
dev-java/openjdk-jre-bin < 11.0.19_p7:11 >= 11.0.19_p7:11
< 17.0.7_p7:17 >= 17.0.7_p7:17
< 8.372_p07:8 >= 8.372_p07:8
Description
===========
Multiple vulnerabilities have been discovered in OpenJDK. Please review
the CVE identifiers referenced below for details.
Impact
======
Please review the referenced CVE identifiers for details.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All OpenJDK users should upgrade to the latest versions:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-8.372_p07"
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-11.0.19_p7"
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-17.0.7_p7"
All OpenJDK JRE binary users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-jre-bin-8.372_p07"
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-jre-bin-11.0.19_p7"
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-jre-bin-17.0.7_p7"
All OpenJDK binary users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-bin-8.372_p07"
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-bin-11.0.19_p7"
# emerge --ask --oneshot --verbose ">=dev-java/openjdk-bin-17.0.7_p7"
References
==========
[ 1 ] CVE-2022-21540
https://nvd.nist.gov/vuln/detail/CVE-2022-21540
[ 2 ] CVE-2022-21541
https://nvd.nist.gov/vuln/detail/CVE-2022-21541
[ 3 ] CVE-2022-21549
https://nvd.nist.gov/vuln/detail/CVE-2022-21549
[ 4 ] CVE-2022-21618
https://nvd.nist.gov/vuln/detail/CVE-2022-21618
[ 5 ] CVE-2022-21619
https://nvd.nist.gov/vuln/detail/CVE-2022-21619
[ 6 ] CVE-2022-21624
https://nvd.nist.gov/vuln/detail/CVE-2022-21624
[ 7 ] CVE-2022-21626
https://nvd.nist.gov/vuln/detail/CVE-2022-21626
[ 8 ] CVE-2022-21628
https://nvd.nist.gov/vuln/detail/CVE-2022-21628
[ 9 ] CVE-2022-34169
https://nvd.nist.gov/vuln/detail/CVE-2022-34169
[ 10 ] CVE-2022-39399
https://nvd.nist.gov/vuln/detail/CVE-2022-39399
[ 11 ] CVE-2022-42920
https://nvd.nist.gov/vuln/detail/CVE-2022-42920
[ 12 ] CVE-2023-21830
https://nvd.nist.gov/vuln/detail/CVE-2023-21830
[ 13 ] CVE-2023-21835
https://nvd.nist.gov/vuln/detail/CVE-2023-21835
[ 14 ] CVE-2023-21843
https://nvd.nist.gov/vuln/detail/CVE-2023-21843
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202401-25
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser. or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
=======
Copyright 2024 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
File Tags
- ActiveX[35] (932)
- Advisory[36] (83,747)
- Arbitrary[37] (16,481)
- BBS[38] (2,859)
- Bypass[39] (1,805)
- CGI[40] (1,031)
- Code Execution[41] (7,474)
- Conference[42] (685)
- Cracker[43] (843)
- CSRF[44] (3,365)
- DoS[45] (24,166)
- Encryption[46] (2,375)
- Exploit[47] (52,413)
- File Inclusion[48] (4,239)
- File Upload[49] (982)
- Firewall[50] (822)
- Info Disclosure[51] (2,817)
- Intrusion Detection[52] (900)
- Java[53] (3,092)
- JavaScript[54] (883)
- Kernel[55] (6,879)
- Local[56] (14,613)
- Magazine[57] (586)
- Overflow[58] (12,923)
- Perl[59] (1,428)
- PHP[60] (5,164)
- Proof of Concept[61] (2,357)
- Protocol[62] (3,673)
- Python[63] (1,579)
- Remote[64] (31,151)
- Root[65] (3,609)
- Rootkit[66] (517)
- Ruby[67] (614)
- Scanner[68] (1,646)
- Security Tool[69] (7,941)
- Shell[70] (3,221)
- Shellcode[71] (1,216)
- Sniffer[72] (898)
- Spoof[73] (2,233)
- SQL Injection[74] (16,464)
- TCP[75] (2,419)
- Trojan[76] (687)
- UDP[77] (896)
- Virus[78] (667)
- Vulnerability[79] (32,256)
- Web[80] (9,806)
- Whitepaper[81] (3,763)
- x86[82] (966)
- XSS[83] (18,085)
- Other[84]
File Archives
- January 2024[85]
- December 2023[86]
- November 2023[87]
- October 2023[88]
- September 2023[89]
- August 2023[90]
- July 2023[91]
- June 2023[92]
- May 2023[93]
- April 2023[94]
- March 2023[95]
- February 2023[96]
- Older[97]
Systems
- AIX[98] (429)
- Apple[99] (2,049)
- BSD[100] (375)
- CentOS[101] (57)
- Cisco[102] (1,926)
- Debian[103] (6,945)
- Fedora[104] (1,693)
- FreeBSD[105] (1,246)
- Gentoo[106] (4,421)
- HPUX[107] (880)
- iOS[108] (366)
- iPhone[109] (108)
- IRIX[110] (220)
- Juniper[111] (69)
- Linux[112] (48,212)
- Mac OS X[113] (691)
- Mandriva[114] (3,105)
- NetBSD[115] (256)
- OpenBSD[116] (487)
- RedHat[117] (14,827)
- Slackware[118] (941)
- Solaris[119] (1,611)
- SUSE[120] (1,444)
- Ubuntu[121] (9,219)
- UNIX[122] (9,352)
- UnixWare[123] (187)
- Windows[124] (6,619)
- Other[125]
- Services
- Security Services[136]
- Hosting By
- Rokasec[137]
Read more https://packetstormsecurity.com/files/176592/glsa-202401-25.txt


