MGASA-2016-0130
Dashboard / Vulnerabilities / MGASA-2016-0130
Summary: Updated java packages fix CVE-2016-0636
Details: Updated java-1.8.0-openjdk packages fix security vulnerability: An improper type safety check was discovered in the Hotspot component. An untrusted Java application or applet could use this flaw to bypass Java Sandbox restrictions (CVE-2016-0636). Also, the icedtea-web package has been updated to version 1.6.2 to fix all known issues in the Java browser plugin.
References: https://advisories.mageia.org/MGASA-2016-0130.html, https://bugs.mageia.org/show_bug.cgi?id=18069, http://mail.openjdk.java.net/pipermail/distro-pkg-dev/2016-February/034831.html, https://rhn.redhat.com/errata/RHSA-2016-0513.html
Affected packages
Package
Name: java-1.8.0-openjdk
Purl: pkg:rpm/mageia/java-1.8.0-openjdk?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
