ALSA-2021:2776
Dashboard / Vulnerabilities / ALSA-2021:2776
ALSA-2021:2776
Summary: Important: java-1.8.0-openjdk security update
Details: The java-1.8.0-openjdk packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit. Security Fix(es): * OpenJDK: Incorrect comparison during range check elimination (Hotspot, 8264066) (CVE-2021-2388) * OpenJDK: FTP PASV command response can cause FtpClient to connect to arbitrary host (Networking, 8258432) (CVE-2021-2341) * OpenJDK: Incorrect verification of JAR files with multiple MANIFEST.MF files (Library, 8260967) (CVE-2021-2369) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://vulners.com/cve/CVE-2021-2341, https://vulners.com/cve/CVE-2021-2369, https://vulners.com/cve/CVE-2021-2388
Affected packages
Package
Name: java-1.8.0-openjdk-accessibility-fastdebug
Purl: pkg:rpm/almalinux/java-1.8.0-openjdk-accessibility-fastdebug
Affected ranges
Type: ECOSYSTEM
Events:
