MGASA-2022-0261
Dashboard / Vulnerabilities / MGASA-2022-0261
MGASA-2022-0261
Summary: Updated java packages fix security vulnerability
Details: OpenJDK: Defective secure validation in Apache Santuario (Libraries, 8278008) (CVE-2022-21476) OpenJDK: Unbounded memory allocation when compiling crafted XPath expressions (JAXP, 8270504) (CVE-2022-21426) OpenJDK: Improper object-to-string conversion in AnnotationInvocationHandler (Libraries, 8277672) (CVE-2022-21434) OpenJDK: Missing check for negative ObjectIdentifier (Libraries, 8275151) (CVE-2022-21443) OpenJDK: URI parsing inconsistencies (JNDI, 8278972) (CVE-2022-21496)
References: https://advisories.mageia.org/MGASA-2022-0261.html, https://bugs.mageia.org/show_bug.cgi?id=30401, https://access.redhat.com/errata/RHSA-2022:1491, https://access.redhat.com/errata/RHSA-2022:1442
Affected packages
Package
Name: java-1.8.0-openjdk
Purl: pkg:rpm/mageia/java-1.8.0-openjdk?arch=source&distro=mageia-8
Affected ranges
Type: ECOSYSTEM
Events:
