Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2020.0182
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2020-0182)
Zusammenfassung:The remote host is missing an update for the 'java-1.8.0-openjdk' package(s) announced via the MGASA-2020-0182 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'java-1.8.0-openjdk' package(s) announced via the MGASA-2020-0182 advisory.

Vulnerability Insight:
Updated java-1.8.0-openjdk packages fix security vulnerabilities:

Misplaced regular expression syntax error check in RegExpScanner (Scripting,
8223898) (CVE-2020-2754)

Incorrect handling of empty string nodes in regular expression Parser
(Scripting, 8223904) (CVE-2020-2755)

Incorrect handling of references to uninitialized class descriptors during
deserialization (Serialization, 8224541) (CVE-2020-2756)

Uncaught InstantiationError exception in ObjectStreamClass (Serialization,
8224549) (CVE-2020-2757)

Unexpected exceptions raised by DOMKeyInfoFactory and DOMXMLSignatureFactory
(Security, 8231415) (CVE-2020-2773)

Re-use of single TLS session for new connections (JSSE, 8234408)
(CVE-2020-2781)

CRLF injection into HTTP headers in HttpServer (Lightweight HTTP Server,
8234825) (CVE-2020-2800)

Incorrect bounds checks in NIO Buffers (Libraries, 8234841)
(CVE-2020-2803)

Incorrect type checks in MethodType.readObject() (Libraries, 8235274)
(CVE-2020-2805)

Regular expression DoS in Scanner (Concurrency, 8236201) (CVE-2020-2830)

Affected Software/OS:
'java-1.8.0-openjdk' package(s) on Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2020-2754
Debian Security Information: DSA-4662 (Google Search)
https://www.debian.org/security/2020/dsa-4662
Debian Security Information: DSA-4668 (Google Search)
https://www.debian.org/security/2020/dsa-4668
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CKAV6KFFAEANXAN73AFTGU7Z6YNRWCXQ/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L7VHC4EW36KZEIDQ56RPCWBZCQELFFKN/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NYHHHZRHXCBGRHGE5UP7UEB4IZ2QX536/
https://www.oracle.com/security-alerts/cpuapr2020.html
SuSE Security Announcement: openSUSE-SU-2020:0757 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00000.html
SuSE Security Announcement: openSUSE-SU-2020:0800 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00023.html
SuSE Security Announcement: openSUSE-SU-2020:0841 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00048.html
https://usn.ubuntu.com/4337-1/
Common Vulnerability Exposure (CVE) ID: CVE-2020-2755
https://security.gentoo.org/glsa/202006-22
https://security.gentoo.org/glsa/202209-15
Common Vulnerability Exposure (CVE) ID: CVE-2020-2756
https://lists.debian.org/debian-lts-announce/2020/04/msg00024.html
Common Vulnerability Exposure (CVE) ID: CVE-2020-2757
Common Vulnerability Exposure (CVE) ID: CVE-2020-2773
Common Vulnerability Exposure (CVE) ID: CVE-2020-2781
Common Vulnerability Exposure (CVE) ID: CVE-2020-2800
Common Vulnerability Exposure (CVE) ID: CVE-2020-2803
Common Vulnerability Exposure (CVE) ID: CVE-2020-2805
Common Vulnerability Exposure (CVE) ID: CVE-2020-2830
CopyrightCopyright (C) 2022 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.