Gentoo Archives: gentoo-announce

From: glsamaker@g.o
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 202209-15 ] Oracle JDK/JRE: Multiple vulnerabilities
Date: Sun, 25 Sep 2022 13:49:57
Message-Id: 166411297586.9.10268413624691973165@90bb6a0775af
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 202209-15
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Oracle JDK/JRE: Multiple vulnerabilities
9 Date: September 25, 2022
10 Bugs: #732630, #717638
11 ID: 202209-15
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Oracle JDK and JRE, the
19 worst of which could result in the arbitrary execution of code.
20
21 Background
22 ==========
23
24 Java Platform, Standard Edition (Java SE) lets you develop and deploy
25 Java applications on desktops and servers, as well as in today's
26 demanding embedded environments. Java offers the rich user interface,
27 performance, versatility, portability, and security that today's
28 applications require.
29
30 Affected packages
31 =================
32
33 -------------------------------------------------------------------
34 Package / Vulnerable / Unaffected
35 -------------------------------------------------------------------
36 1 dev-java/oracle-jdk-bin <= 11.0.2 Vulnerable!
37 2 dev-java/oracle-jre-bin <= 1.8.0.202 Vulnerable!
38
39 Description
40 ===========
41
42 Multiple vulnerabilities have been discovered in Oracle's JDK and JRE
43 software suites. Please review the CVE identifiers referenced below for
44 details.
45
46 Impact
47 ======
48
49 Certain uses of untrusted data by Oracle JDK and JRE could result in
50 arbitrary code execution.
51
52 Workaround
53 ==========
54
55 There is no known workaround at this time.
56
57 Resolution
58 ==========
59
60 Gentoo has discontinued support for the Oracle JDK and JRE. We recommend
61 that users remove it, and use dev-java/openjdk, dev-java/openjdk-bin, or
62 dev-java/openjdk-jre-bin instead:
63
64 # emerge --ask --depclean "dev-java/oracle-jre-bin"
65 # emerge --ask --depclean "dev-java/oracle-jdk-bin"
66
67 References
68 ==========
69
70 [ 1 ] CVE-2020-2585
71 https://nvd.nist.gov/vuln/detail/CVE-2020-2585
72 [ 2 ] CVE-2020-2755
73 https://nvd.nist.gov/vuln/detail/CVE-2020-2755
74 [ 3 ] CVE-2020-2756
75 https://nvd.nist.gov/vuln/detail/CVE-2020-2756
76 [ 4 ] CVE-2020-2757
77 https://nvd.nist.gov/vuln/detail/CVE-2020-2757
78 [ 5 ] CVE-2020-2773
79 https://nvd.nist.gov/vuln/detail/CVE-2020-2773
80 [ 6 ] CVE-2020-2781
81 https://nvd.nist.gov/vuln/detail/CVE-2020-2781
82 [ 7 ] CVE-2020-2800
83 https://nvd.nist.gov/vuln/detail/CVE-2020-2800
84 [ 8 ] CVE-2020-2803
85 https://nvd.nist.gov/vuln/detail/CVE-2020-2803
86 [ 9 ] CVE-2020-2805
87 https://nvd.nist.gov/vuln/detail/CVE-2020-2805
88 [ 10 ] CVE-2020-14556
89 https://nvd.nist.gov/vuln/detail/CVE-2020-14556
90 [ 11 ] CVE-2020-14562
91 https://nvd.nist.gov/vuln/detail/CVE-2020-14562
92 [ 12 ] CVE-2020-14573
93 https://nvd.nist.gov/vuln/detail/CVE-2020-14573
94 [ 13 ] CVE-2020-14577
95 https://nvd.nist.gov/vuln/detail/CVE-2020-14577
96 [ 14 ] CVE-2020-14578
97 https://nvd.nist.gov/vuln/detail/CVE-2020-14578
98 [ 15 ] CVE-2020-14579
99 https://nvd.nist.gov/vuln/detail/CVE-2020-14579
100 [ 16 ] CVE-2020-14581
101 https://nvd.nist.gov/vuln/detail/CVE-2020-14581
102 [ 17 ] CVE-2020-14583
103 https://nvd.nist.gov/vuln/detail/CVE-2020-14583
104 [ 18 ] CVE-2020-14593
105 https://nvd.nist.gov/vuln/detail/CVE-2020-14593
106 [ 19 ] CVE-2020-14621
107 https://nvd.nist.gov/vuln/detail/CVE-2020-14621
108 [ 20 ] CVE-2020-14664
109 https://nvd.nist.gov/vuln/detail/CVE-2020-14664
110
111 Availability
112 ============
113
114 This GLSA and any updates to it are available for viewing at
115 the Gentoo Security Website:
116
117 https://security.gentoo.org/glsa/202209-15
118
119 Concerns?
120 =========
121
122 Security is a primary focus of Gentoo Linux and ensuring the
123 confidentiality and security of our users' machines is of utmost
124 importance to us. Any security concerns should be addressed to
125 security@g.o or alternatively, you may file a bug at
126 https://bugs.gentoo.org.
127
128 License
129 =======
130
131 Copyright 2022 Gentoo Foundation, Inc; referenced text
132 belongs to its owner(s).
133
134 The contents of this document are licensed under the
135 Creative Commons - Attribution / Share Alike license.
136
137 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature