RLSA-2023:1880 --- java-11-openjdkID: oval:org.secpod.oval:def:5800164 | Date: (C)2023-06-19 (M)2024-02-19 |
Class: PATCH | Family: unix |
The java-11-openjdk packages provide the OpenJDK 11 Java Runtime Environment and the OpenJDK 11 Java Software Development Kit. Security Fix: * OpenJDK: improper connection handling during TLS handshake * OpenJDK: Swing HTML parsing issue * OpenJDK: incorrect enqueue of references in garbage collector * OpenJDK: certificate validation issue in TLS session negotiation * OpenJDK: missing string checks for NULL characters * OpenJDK: incorrect handling of NULL characters in ProcessBuilder * OpenJDK: missing check for slash characters in URI-to-path conversion For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section.