RHSA-2020:0128-01 -- Redhat java-11-openjdkID: oval:org.secpod.oval:def:503485 | Date: (C)2020-01-23 (M)2022-11-07 |
Class: PATCH | Family: unix |
The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit. Security Fix: * OpenJDK: Use of unsafe RSA-MD5 checkum in Kerberos TGS * OpenJDK: Serialization filter changes via jdk.serialFilter property modification * OpenJDK: Improper checks of SASL message properties in GssKrb5Base * OpenJDK: Incorrect isBuiltinStreamHandler causing URL normalization issues * OpenJDK: Excessive memory usage in OID processing in X.509 certificate parsing * OpenJDK: Incorrect handling of unexpected CertificateVerify TLS handshake messages * OpenJDK: Incorrect exception processing during deserialization in BeanContextSupport For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.
Platform: |
Red Hat Enterprise Linux 8 |