| Summary: | java-1.8.0-openjdk new security issues | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | David Walser <luigiwalser> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | andrewsfarm, brtians1, herman.viaene, mageia, marja11, nicolas.salguero, sysadmin-bugs, tmb |
| Version: | 6 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA6-32-OK MGA6-64-OK | ||
| Source RPM: | java-1.8.0-openjdk-1.8.0.172-1.b11.4.mga7.src.rpm | CVE: | |
| Status comment: | |||
|
Description
David Walser
2018-07-23 16:20:02 CEST
David Walser
2018-07-23 16:20:18 CEST
Whiteboard:
(none) =>
MGA6TOO, MGA5TOO
Marja Van Waes
2018-07-23 18:10:35 CEST
Assignee:
bugsquad =>
java Fedora has issued an advisory for this on July 29: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/SQOPSPGKVQCFIE2XTLU2LMNWETD7N4HS/ Suggested advisory: ======================== The updated packages fix some security vulnerabilities. References: https://access.redhat.com/errata/RHSA-2018:2242 http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html ======================== Updated package in core/updates_testing: ======================== java-1.8.0-openjdk-1.8.0.181-1.b13.2.mga6 java-1.8.0-openjdk-headless-1.8.0.181-1.b13.2.mga6 java-1.8.0-openjdk-devel-1.8.0.181-1.b13.2.mga6 java-1.8.0-openjdk-demo-1.8.0.181-1.b13.2.mga6 java-1.8.0-openjdk-src-1.8.0.181-1.b13.2.mga6 java-1.8.0-openjdk-javadoc-1.8.0.181-1.b13.2.mga6 java-1.8.0-openjdk-javadoc-zip-1.8.0.181-1.b13.2.mga6 java-1.8.0-openjdk-accessibility-1.8.0.181-1.b13.2.mga6 from SRPMS: java-1.8.0-openjdk-1.8.0.181-1.b13.2.mga6.src.rpm CC:
(none) =>
nicolas.salguero MGA6-32 MATE on IBM Thinkpad R50e No installation issues. Ref to bug 22929 for testing at CLI: $ java -version openjdk version "1.8.0_181" OpenJDK Runtime Environment (build 1.8.0_181-b13) OpenJDK Server VM (build 25.181-b13, mixed mode) Trying - https://www.java.com/verify/ - results in: "Starting with Firefox Version 52 (released in March 2017), Firefox has limited support for plug-ins, and therefore will not run Java. " Further info leads to above java version command, so that should be OK. Testing helloworld as in the openjfx update bug23349 is OK. CC:
(none) =>
herman.viaene It's been a very long time since I knowingly did anything with java in Firefox. I installed this update on one of my 64-bit Plasma systems, then tried the url provided by Herman, and got the same result. So, I installed the java-1.8.0-openjdk-demo-1.8.0.181-1.b13.2.mga6 package, which wasn't presented as an update, and tried one or two of the demos, only to learn once again that I needed the IcedTea-web plugin to run them in Firefox 52 ESR. (As I said, it's been a long time.) Once everything needed was installed, the demos ran perfectly. So, I'm going to give this a 64-bit OK. CC:
(none) =>
andrewsfarm $ uname -a Linux localhost 4.14.65-desktop-1.mga6 #1 SMP Sat Aug 18 14:50:29 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux Installed openjdk The following 8 packages are going to be installed: - java-1.8.0-openjdk-1.8.0.181-1.b13.2.mga6.x86_64 - java-1.8.0-openjdk-accessibility-1.8.0.181-1.b13.2.mga6.x86_64 - java-1.8.0-openjdk-demo-1.8.0.181-1.b13.2.mga6.x86_64 - java-1.8.0-openjdk-devel-1.8.0.181-1.b13.2.mga6.x86_64 - java-1.8.0-openjdk-headless-1.8.0.181-1.b13.2.mga6.x86_64 - java-1.8.0-openjdk-javadoc-zip-1.8.0.181-1.b13.2.mga6.noarch - java-1.8.0-openjfx-1.8.0.181-1.b12.2.mga6.x86_64 - java-atk-wrapper-0.33.2-3.mga6.x86_6 verified version Installed Eclipse Able to open and navigate in eclipse. This is good on 64-bit. CC:
(none) =>
brtians1 Validating... Keywords:
(none) =>
validated_update
Thomas Backlund
2018-09-02 20:24:56 CEST
Keywords:
(none) =>
advisory An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2018-0366.html Status:
ASSIGNED =>
RESOLVED |