SUSE-SU-2022:3092-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3092-1
SUSE-SU-2022:3092-1
Summary: Security update for java-1_8_0-openj9
Details: This update for java-1_8_0-openj9 fixes the following issues: - Updated to OpenJDK 8u345 build 01 with OpenJ9 0.33.0 virtual machine: - CVE-2022-34169: Fixed an integer truncation issue in the Xalan Java XSLT library that occurred when processing malicious stylesheets (bsc#1201684). - CVE-2022-21541: Fixed a potential bypass of sandbox restrictions in the Hotspot component (bsc#1201692). - CVE-2022-21540: Fixed a potential bypass of sandbox restrictions in the Hotspot component (bsc#1201694). - Updated to OpenJDK 8u332 build 09 with OpenJ9 0.32.0 virtual machine: - CVE-2021-41041: Failed an issue that could allow unverified methods to be invoked using MethodHandles (bsc#1198935). - CVE-2022-21426: Fixed a remote partial denial of service issue (component: JAXP) (bsc#1198672). - CVE-2022-21434: Fixed an issue that could allow a remote attacker to update, insert or delete data (component: Libraries) (bsc#1198674). - CVE-2022-21443: Fixed a remote partial denial of service issue (component: Libraries) (bsc#1198675). - CVE-2022-21476: Fixed an issue that could allow unauthorized access to confidential data (component: Libraries) (bsc#1198671). - CVE-2022-21496: Fixed an issue that could allow a remote attacker to update, insert or delete data (component: JNDI) (bsc#1198673).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223092-1/, https://bugzilla.suse.com/1198671, https://bugzilla.suse.com/1198672, https://bugzilla.suse.com/1198673, https://bugzilla.suse.com/1198674, https://bugzilla.suse.com/1198675, https://bugzilla.suse.com/1198935, https://bugzilla.suse.com/1201684, https://bugzilla.suse.com/1201692, https://bugzilla.suse.com/1201694, https://www.suse.com/security/cve/CVE-2021-41041, https://www.suse.com/security/cve/CVE-2022-21426, https://www.suse.com/security/cve/CVE-2022-21434, https://www.suse.com/security/cve/CVE-2022-21443, https://www.suse.com/security/cve/CVE-2022-21476, https://www.suse.com/security/cve/CVE-2022-21496, https://www.suse.com/security/cve/CVE-2022-21540, https://www.suse.com/security/cve/CVE-2022-21541, https://www.suse.com/security/cve/CVE-2022-34169
Affected packages
Package
Name: java-1_8_0-openj9
Purl: pkg:rpm/opensuse/java-1_8_0-openj9&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
