USN-6077-1
Dashboard / Vulnerabilities / USN-6077-1
USN-6077-1
Summary: openjdk-8, openjdk-lts, openjdk-17, openjdk-20 vulnerabilities
Details: Ben Smyth discovered that OpenJDK incorrectly handled half-duplex connections during TLS handshake. A remote attacker could possibly use this issue to insert, edit or obtain sensitive information. (CVE-2023-21930) It was discovered that OpenJDK incorrectly handled certain inputs. An attacker could possibly use this issue to insert, edit or obtain sensitive information. (CVE-2023-21937) It was discovered that OpenJDK incorrectly handled command arguments. An attacker could possibly use this issue to insert, edit or obtain sensitive information. (CVE-2023-21938) It was discovered that OpenJDK incorrectly validated HTML documents. An attacker could possibly use this issue to insert, edit or obtain sensitive information. (CVE-2023-21939) Ramki Ramakrishna discovered that OpenJDK incorrectly handled garbage collection. An attacker could possibly use this issue to bypass Java sandbox restrictions. (CVE-2023-21954) Jonathan Looney discovered that OpenJDK incorrectly handled certificate chains during TLS session negotiation. A remote attacker could possibly use this issue to cause a denial of service. (CVE-2023-21967) Adam Reziouk discovered that OpenJDK incorrectly sanitized URIs. An attacker could possibly use this issue to bypass Java sandbox restrictions. (CVE-2023-21968)
References: https://ubuntu.com/security/notices/USN-6077-1, https://ubuntu.com/security/CVE-2023-21930, https://ubuntu.com/security/CVE-2023-21937, https://ubuntu.com/security/CVE-2023-21938, https://ubuntu.com/security/CVE-2023-21939, https://ubuntu.com/security/CVE-2023-21954, https://ubuntu.com/security/CVE-2023-21967, https://ubuntu.com/security/CVE-2023-21968
Affected packages
Package
Name: openjdk-8
Purl: pkg:deb/ubuntu/openjdk-8?arch=source&distro=esm-infra%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
