Bug 26520 - java-1.8.0-openjdk new security issues
Summary: java-1.8.0-openjdk new security issues
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2020-04-21 21:49 CEST by David Walser
Modified: 2020-04-24 19:05 CEST (History)
6 users (show)

See Also:
Source RPM: java-1.8.0-openjdk-1.8.0.242-1.b07.1.mga7.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2020-04-21 21:49:08 CEST
April 2020 Oracle CPU:
https://www.oracle.com/security-alerts/cpuapr2020.html#AppendixJAVA

RedHat has issued an advisory for this today (April 21):
https://access.redhat.com/errata/RHSA-2020:1512

Nicolas has already built this update.

Suggested advisory:
========================

Updated java-1.8.0-openjdk packages fix security vulnerabilities:

Incorrect bounds checks in NIO Buffers (Libraries, 8234841) (CVE-2020-2803)

Incorrect type checks in MethodType.readObject() (Libraries, 8235274) (CVE-2020-2805)

Unexpected exceptions raised by DOMKeyInfoFactory and DOMXMLSignatureFactory (Security, 8231415) (CVE-2020-2773)

Re-use of single TLS session for new connections (JSSE, 8234408) (CVE-2020-2781)

CRLF injection into HTTP headers in HttpServer (Lightweight HTTP Server, 8234825) (CVE-2020-2800)

Regular expression DoS in Scanner (Concurrency, 8236201) (CVE-2020-2830)

Misplaced regular expression syntax error check in RegExpScanner (Scripting, 8223898) (CVE-2020-2754)

Incorrect handling of empty string nodes in regular expression Parser (Scripting, 8223904) (CVE-2020-2755)

Incorrect handling of references to uninitialized class descriptors during deserialization (Serialization, 8224541) (CVE-2020-2756)

Uncaught InstantiationError exception in ObjectStreamClass (Serialization, 8224549) (CVE-2020-2757)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2754
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2755
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2756
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2757
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2773
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2781
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2800
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2803
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2805
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2830
https://www.oracle.com/security-alerts/cpuapr2020.html#AppendixJAVA
https://access.redhat.com/errata/RHSA-2020:1512
========================

Updated packages in core/updates_testing:
========================
java-1.8.0-openjdk-1.8.0.252-1.b09.1.mga7
java-1.8.0-openjdk-headless-1.8.0.252-1.b09.1.mga7
java-1.8.0-openjdk-devel-1.8.0.252-1.b09.1.mga7
java-1.8.0-openjdk-demo-1.8.0.252-1.b09.1.mga7
java-1.8.0-openjdk-src-1.8.0.252-1.b09.1.mga7
java-1.8.0-openjdk-javadoc-1.8.0.252-1.b09.1.mga7
java-1.8.0-openjdk-javadoc-zip-1.8.0.252-1.b09.1.mga7
java-1.8.0-openjdk-accessibility-1.8.0.252-1.b09.1.mga7
java-1.8.0-openjdk-openjfx-1.8.0.252-1.b09.1.mga7
java-1.8.0-openjdk-openjfx-devel-1.8.0.252-1.b09.1.mga7

from java-1.8.0-openjdk-1.8.0.252-1.b09.1.mga7.src.rpm
David Walser 2020-04-21 21:49:17 CEST

CC: (none) => nicolas.salguero

Comment 1 Herman Viaene 2020-04-22 14:06:11 CEST
MGA7-64 Plasma on Lenovo B50
No installation issues
Ref bug 20220 for test and test file.
$ java -version
openjdk version "1.8.0_252"
OpenJDK Runtime Environment (build 1.8.0_252-b09)
OpenJDK 64-Bit Server VM (build 25.252-b09, mixed mode)
[tester7@mach5 Documents]$ javac helloworld.java 
[tester7@mach5 Documents]$ java helloworld
Hello World!
Hello World!
because I pressed the button twice.
OK for me.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA7-64-OK

Comment 2 Jose Manuel López 2020-04-23 06:07:45 CEST
I have installed in MGA7-64 VB, works fine. I've opened a java application and runs correctly.

[jose@localhost ~]$ java -version
openjdk version "1.8.0_252"
OpenJDK Runtime Environment (build 1.8.0_252-b09)
OpenJDK 64-Bit Server VM (build 25.252-b09, mixed mode)
[jose@localhost ~]$ 



Greetings!

CC: (none) => joselp

Comment 3 Thomas Andrews 2020-04-23 22:38:48 CEST
Validating. Advisory in Comment 0.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Thomas Backlund 2020-04-24 17:51:39 CEST

CC: (none) => tmb
Keywords: (none) => advisory

Comment 4 Mageia Robot 2020-04-24 19:05:44 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2020-0182.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.