Bug 23343 - java-1.8.0-openjdk new security issues
Summary: java-1.8.0-openjdk new security issues
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 6
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA6-32-OK MGA6-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2018-07-23 16:20 CEST by David Walser
Modified: 2018-09-02 21:08 CEST (History)
8 users (show)

See Also:
Source RPM: java-1.8.0-openjdk-1.8.0.172-1.b11.4.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2018-07-23 16:20:02 CEST
RedHat has issued an advisory today (July 23):
https://access.redhat.com/errata/RHSA-2018:2242

Corresponding Oracle CPU:
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html

The update was just committed to Fedora git, so we can start syncing it in soon.
David Walser 2018-07-23 16:20:18 CEST

Whiteboard: (none) => MGA6TOO, MGA5TOO

Marja Van Waes 2018-07-23 18:10:35 CEST

Assignee: bugsquad => java
CC: (none) => mageia, marja11

Comment 1 David Walser 2018-08-02 18:14:54 CEST
Fedora has issued an advisory for this on July 29:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/SQOPSPGKVQCFIE2XTLU2LMNWETD7N4HS/
Comment 2 Nicolas Salguero 2018-08-28 16:50:47 CEST
Suggested advisory:
========================

The updated packages fix some security vulnerabilities.

References:
https://access.redhat.com/errata/RHSA-2018:2242
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
========================

Updated package in core/updates_testing:
========================
java-1.8.0-openjdk-1.8.0.181-1.b13.2.mga6
java-1.8.0-openjdk-headless-1.8.0.181-1.b13.2.mga6
java-1.8.0-openjdk-devel-1.8.0.181-1.b13.2.mga6
java-1.8.0-openjdk-demo-1.8.0.181-1.b13.2.mga6
java-1.8.0-openjdk-src-1.8.0.181-1.b13.2.mga6
java-1.8.0-openjdk-javadoc-1.8.0.181-1.b13.2.mga6
java-1.8.0-openjdk-javadoc-zip-1.8.0.181-1.b13.2.mga6
java-1.8.0-openjdk-accessibility-1.8.0.181-1.b13.2.mga6

from SRPMS:
java-1.8.0-openjdk-1.8.0.181-1.b13.2.mga6.src.rpm

CC: (none) => nicolas.salguero
Whiteboard: MGA6TOO, MGA5TOO => (none)
Version: Cauldron => 6
Status: NEW => ASSIGNED
Assignee: java => qa-bugs

Comment 3 Herman Viaene 2018-08-29 10:21:37 CEST
MGA6-32 MATE on IBM Thinkpad R50e
No installation issues.
Ref to bug 22929 for testing
at CLI:
$ java -version
openjdk version "1.8.0_181"
OpenJDK Runtime Environment (build 1.8.0_181-b13)
OpenJDK Server VM (build 25.181-b13, mixed mode)
Trying - https://www.java.com/verify/ - results in:
"Starting with Firefox Version 52 (released in March 2017), Firefox has limited support for plug-ins, and therefore will not run Java. "
Further info leads to above java version command, so that should be OK.
Testing helloworld as in the openjfx update bug23349 is OK.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA6-32-OK

Comment 4 Thomas Andrews 2018-08-29 21:30:31 CEST
It's been a very long time since I knowingly did anything with java in Firefox. I installed this update on one of my 64-bit Plasma systems, then tried the url provided by Herman, and got the same result. 

So, I installed the java-1.8.0-openjdk-demo-1.8.0.181-1.b13.2.mga6 package, which wasn't presented as an update, and tried one or two of the demos, only to learn once again that I needed the IcedTea-web plugin to run them in Firefox 52 ESR. (As I said, it's been a long time.)

Once everything needed was installed, the demos ran perfectly. So, I'm going to give this a 64-bit OK.

CC: (none) => andrewsfarm
Whiteboard: MGA6-32-OK => MGA6-32-OK MGA6-64-OK

Comment 5 Brian Rockwell 2018-09-02 17:13:15 CEST
$ uname -a
Linux localhost 4.14.65-desktop-1.mga6 #1 SMP Sat Aug 18 14:50:29 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux


Installed openjdk

The following 8 packages are going to be installed:

- java-1.8.0-openjdk-1.8.0.181-1.b13.2.mga6.x86_64
- java-1.8.0-openjdk-accessibility-1.8.0.181-1.b13.2.mga6.x86_64
- java-1.8.0-openjdk-demo-1.8.0.181-1.b13.2.mga6.x86_64
- java-1.8.0-openjdk-devel-1.8.0.181-1.b13.2.mga6.x86_64
- java-1.8.0-openjdk-headless-1.8.0.181-1.b13.2.mga6.x86_64
- java-1.8.0-openjdk-javadoc-zip-1.8.0.181-1.b13.2.mga6.noarch
- java-1.8.0-openjfx-1.8.0.181-1.b12.2.mga6.x86_64
- java-atk-wrapper-0.33.2-3.mga6.x86_6

verified version

Installed Eclipse

Able to open and navigate in eclipse.

This is good on 64-bit.

CC: (none) => brtians1

Comment 6 Thomas Andrews 2018-09-02 19:13:42 CEST
Validating...

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Thomas Backlund 2018-09-02 20:24:56 CEST

Keywords: (none) => advisory
CC: (none) => tmb

Comment 7 Mageia Robot 2018-09-02 21:08:26 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2018-0366.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.