Login
Newsletter
Werbung

Sicherheit: Denial of Service in OpenJDK
Aktuelle Meldungen Distributionen
Name: Denial of Service in OpenJDK
ID: USN-4726-1
Distribution: Ubuntu
Plattformen: Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 20.10
Datum: Di, 9. Februar 2021, 23:48
Referenzen: Keine Angabe
Applikationen: OpenJDK

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--===============8656321531017927763==
Content-Type: multipart/signed; micalg=pgp-sha256;
protocol="application/pgp-signature";
boundary="VKJfJOq8tWLwdFEx4Zhf3trOzEFUHIoxy"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--VKJfJOq8tWLwdFEx4Zhf3trOzEFUHIoxy
Content-Type: multipart/mixed;
boundary="pLp7RvGQhJJCM3U8RXVFZqm1Thd4XEugB"

--pLp7RvGQhJJCM3U8RXVFZqm1Thd4XEugB
Content-Type: text/plain; charset=utf-
Content-Transfer-Encoding: quoted-printable
Content-Language: en-US

==========================================================================
Ubuntu Security Notice USN-4726-1
February 09, 2021

openjdk-8, openjdk-lts vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

OpenJDK could be made to crash if it received specially crafted
input.

Software Description:
- openjdk-8: Open Source Java implementation
- openjdk-lts: Open Source Java implementation

Details:

It was discovered that OpenJDK incorrectly handled the direct buffering of
characters. An attacker could use this issue to cause OpenJDK to crash,
resulting in a denial of service, or cause other unspecified impact.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
openjdk-11-jdk 11.0.10+9-0ubuntu1~20.10
openjdk-11-jre 11.0.10+9-0ubuntu1~20.10
openjdk-11-jre-headless 11.0.10+9-0ubuntu1~20.10
openjdk-11-jre-zero 11.0.10+9-0ubuntu1~20.10
openjdk-8-jdk 8u282-b08-0ubuntu1~20.10
openjdk-8-jre 8u282-b08-0ubuntu1~20.10
openjdk-8-jre-headless 8u282-b08-0ubuntu1~20.10
openjdk-8-jre-zero 8u282-b08-0ubuntu1~20.10

Ubuntu 20.04 LTS:
openjdk-11-jdk 11.0.10+9-0ubuntu1~20.04
openjdk-11-jre 11.0.10+9-0ubuntu1~20.04
openjdk-11-jre-headless 11.0.10+9-0ubuntu1~20.04
openjdk-11-jre-zero 11.0.10+9-0ubuntu1~20.04
openjdk-8-jdk 8u282-b08-0ubuntu1~20.04
openjdk-8-jre 8u282-b08-0ubuntu1~20.04
openjdk-8-jre-headless 8u282-b08-0ubuntu1~20.04
openjdk-8-jre-zero 8u282-b08-0ubuntu1~20.04

Ubuntu 18.04 LTS:
openjdk-11-jdk 11.0.10+9-0ubuntu1~18.04
openjdk-11-jre 11.0.10+9-0ubuntu1~18.04
openjdk-11-jre-headless 11.0.10+9-0ubuntu1~18.04
openjdk-11-jre-zero 11.0.10+9-0ubuntu1~18.04
openjdk-8-jdk 8u282-b08-0ubuntu1~18.04
openjdk-8-jre 8u282-b08-0ubuntu1~18.04
openjdk-8-jre-headless 8u282-b08-0ubuntu1~18.04
openjdk-8-jre-zero 8u282-b08-0ubuntu1~18.04

Ubuntu 16.04 LTS:
openjdk-8-jdk 8u282-b08-0ubuntu1~16.04
openjdk-8-jre 8u282-b08-0ubuntu1~16.04
openjdk-8-jre-headless 8u282-b08-0ubuntu1~16.04
openjdk-8-jre-jamvm 8u282-b08-0ubuntu1~16.04
openjdk-8-jre-zero 8u282-b08-0ubuntu1~16.04

This update uses a new upstream release, which includes additional bug
fixes. After a standard system update you need to restart any Java
applications or applets to make all the necessary changes.

References:
https://usn.ubuntu.com/4726-1
https://launchpad.net/bugs/1914824

Package Information:
https://launchpad.net/ubuntu/+source/openjdk-8/8u282-b08-0ubuntu1~20.10
https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.10+9-0ubuntu1~20.10
https://launchpad.net/ubuntu/+source/openjdk-8/8u282-b08-0ubuntu1~20.04
https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.10+9-0ubuntu1~20.04
https://launchpad.net/ubuntu/+source/openjdk-8/8u282-b08-0ubuntu1~18.04
https://launchpad.net/ubuntu/+source/openjdk-lts/11.0.10+9-0ubuntu1~18.04
https://launchpad.net/ubuntu/+source/openjdk-8/8u282-b08-0ubuntu1~16.04



--pLp7RvGQhJJCM3U8RXVFZqm1Thd4XEugB--

--VKJfJOq8tWLwdFEx4Zhf3trOzEFUHIoxy
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEElnO/d49FoUPK9fwytGdj0GOh2+wFAmAiz/sACgkQtGdj0GOh
2+zZQgf8CCSS8oIWpeSmCaSp1Y+d8DUie7HWpeAh1Gw00CVgvQcc5FhxR12jRMjK
QHXaY+ZG5Z2JWwj1GmmckoPvk14QlOwSSNgk48xTWS+wgBLZyAV/so0FKato+lRU
VbOFWekoo0GtGHe907LPhEAJ9x5Lz9IqTa+XkdGA79ZNijJpY5duu1y5we3X9Adu
Ycipu/oVOmqdDjtZP07TmUacTgOAi3TZlO69nYb3q5mtookMywG69P1Kh3E5qsCj
ymPvvfy6qDZWBjmHUwOHOKHKmJVU3d86n2eZWDVkxBvQNOLPOQXXQYpPdXkMOyFy
8R8WdONXYXP1kkvobYcvVX6VWMwEhA==
=TlHD
-----END PGP SIGNATURE-----

--VKJfJOq8tWLwdFEx4Zhf3trOzEFUHIoxy--


--===============8656321531017927763==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

LS0gCnVidW50dS1zZWN1cml0eS1hbm5vdW5jZSBtYWlsaW5nIGxpc3QKdWJ1bnR1LXNlY3VyaXR5
LWFubm91bmNlQGxpc3RzLnVidW50dS5jb20KTW9kaWZ5IHNldHRpbmdzIG9yIHVuc3Vic2NyaWJl
IGF0OiBodHRwczovL2xpc3RzLnVidW50dS5jb20vbWFpbG1hbi9saXN0aW5mby91YnVudHUtc2Vj
dXJpdHktYW5ub3VuY2UK

--===============8656321531017927763==--
Pro-Linux
Pro-Linux @Facebook
Neue Nachrichten
Werbung