RHSA-2023:4233-01 -- Redhat java-11-openjdkID: oval:org.secpod.oval:def:507863 | Date: (C)2023-07-25 (M)2024-02-19 |
Class: PATCH | Family: unix |
The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit. Security Fix: * OpenJDK: ZIP file parsing infinite loop * OpenJDK: weakness in AES implementation * OpenJDK: improper handling of slash characters in URI-to-path conversion * harfbuzz: OpenJDK: O growth via consecutive marks * OpenJDK: HTTP client insufficient file name validation * OpenJDK: array indexing integer overflow issue For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Bug Fix: * Prepare for the next quarterly OpenJDK upstream release
Platform: |
Red Hat Enterprise Linux 7 |