[CLSA-2023:1675986440] java-1.8.0-openjdk: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2023-02-09
Description:
- Upgrade to openjdk-shenandoah-jdk8u-shenandoah-jdk8u362-b09. That fixes following CVEs: - CVE-2023-21830: Improper restrictions in CORBA deserialization (Serialization, 8285021) - CVE-2023-21843: Soundbank URL remote loading (Sound, 8293742) - Update tzdata requirement to 2022g to match JDK-8297804 - Remove patches which are in upstream now - Remove the obsolete rh1163501 patch
Updated packages:
  • java-1.8.0-openjdk-1.8.0.362.b09-1.el6.tuxcare.els1.x86_64.rpm
    sha:94925eda80891da5b8e29e97917201fd62a764e5
  • java-1.8.0-openjdk-debug-1.8.0.362.b09-1.el6.tuxcare.els1.x86_64.rpm
    sha:420a2f65a9f6a77cee09cbb346b53f7ee552f0fa
  • java-1.8.0-openjdk-demo-1.8.0.362.b09-1.el6.tuxcare.els1.x86_64.rpm
    sha:ec2363d4a73ac4db85e26a652522fd22d8895032
  • java-1.8.0-openjdk-demo-debug-1.8.0.362.b09-1.el6.tuxcare.els1.x86_64.rpm
    sha:b978f3d4c46b1e8f43c0141e9b1d091c6a2b8305
  • java-1.8.0-openjdk-devel-1.8.0.362.b09-1.el6.tuxcare.els1.x86_64.rpm
    sha:2e6c867bc0a8e06d769d8b050f93e77606a31da7
  • java-1.8.0-openjdk-devel-debug-1.8.0.362.b09-1.el6.tuxcare.els1.x86_64.rpm
    sha:859e0cf10c85694571ee3cfaf7f8026efa579f8f
  • java-1.8.0-openjdk-headless-1.8.0.362.b09-1.el6.tuxcare.els1.x86_64.rpm
    sha:8b3cc39733c9c44e7fa6fb895046c1a70dd9e810
  • java-1.8.0-openjdk-headless-debug-1.8.0.362.b09-1.el6.tuxcare.els1.x86_64.rpm
    sha:73202891c91a481c62a27c5eb4285a52b461f9e3
  • java-1.8.0-openjdk-javadoc-1.8.0.362.b09-1.el6.tuxcare.els1.noarch.rpm
    sha:ea610234a9b62b604c8c81417ad5bdd2741ad309
  • java-1.8.0-openjdk-javadoc-debug-1.8.0.362.b09-1.el6.tuxcare.els1.noarch.rpm
    sha:da1002989f6fa4199cbde54d4e8e0edc92f8ee8e
  • java-1.8.0-openjdk-src-1.8.0.362.b09-1.el6.tuxcare.els1.x86_64.rpm
    sha:94ab3df2103b1acd178a46127756b92a7281671d
  • java-1.8.0-openjdk-src-debug-1.8.0.362.b09-1.el6.tuxcare.els1.x86_64.rpm
    sha:6e073720519db2f27b3645f035fba134fe46d251
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.