GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Thu Aug 15, 2019 8:26 pm Post subject: [ GLSA 201908-10 ] Oracle JDK/JRE |
|
|
Gentoo Linux Security Advisory
Title: Oracle JDK/JRE: Multiple vulnerabilities (GLSA 201908-10)
Severity: normal
Exploitable: remote
Date: 2019-08-15
Bug(s): #668948, #691336
ID: 201908-10
Synopsis
Multiple vulnerabilities have been found in Oracle’s JDK and JRE
software suites.
Background
Java Platform, Standard Edition (Java SE) lets you develop and deploy
Java applications on desktops and servers, as well as in today’s
demanding embedded environments. Java offers the rich user interface,
performance, versatility, portability, and security that today’s
applications require.
Affected Packages
Package: dev-java/oracle-jdk-bin
Vulnerable: < 1.8.0.202
Unaffected: >= 1.8.0.202
Architectures: All supported architectures
Package: dev-java/oracle-jre-bin
Vulnerable: < 1.8.0.202
Unaffected: >= 1.8.0.202
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in Oracle’s JDK and JRE
software suites. Please review the CVE identifiers referenced below for
details.
Impact
Please review the referenced CVE identifiers for details.
Workaround
There is no known workaround at this time.
Resolution
All Oracle JDK bin users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=dev-java/oracle-jdk-bin-1.8.0.202:1.8"
| All Oracle JRE bin users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=dev-java/oracle-jre-bin-1.8.0.202:1.8"
|
References
CVE-2018-13785
CVE-2018-3136
CVE-2018-3139
CVE-2018-3149
CVE-2018-3150
CVE-2018-3157
CVE-2018-3169
CVE-2018-3180
CVE-2018-3183
CVE-2018-3209
CVE-2018-3211
CVE-2018-3214
CVE-2019-2602
CVE-2019-2684
CVE-2019-2697
CVE-2019-2698
CVE-2019-2699 |
|