[RHSA-2019:2592] java-1.8.0-ibm security update

Severity Important
Affected Packages 22
CVEs 7

IBM Java SE version 8 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.

This update upgrades IBM Java SE 8 to version 8 SR5-FP40.

Security Fix(es):

  • IBM JDK: Out-of-bounds access in the String.getBytes method (CVE-2019-11772)

  • IBM JDK: Failure to privatize a value pulled out of the loop by versioning (CVE-2019-11775)

  • OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762)

  • OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769)

  • OpenJDK: Missing URL format validation (Networking, 8221518) (CVE-2019-2816)

  • OpenJDK: Insufficient restriction of privileges in AccessController (Security, 8216381) (CVE-2019-2786)

  • libpng: use-after-free in png_image_free in png.c (CVE-2019-7317)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Package Affected Version
pkg:rpm/redhat/java-1.8.0-ibm?arch=x86_64&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm?arch=s390x&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm?arch=ppc64&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm?arch=i686&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-src?arch=x86_64&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-src?arch=s390x&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-src?arch=ppc64&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-src?arch=i686&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-plugin?arch=x86_64&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-plugin?arch=i686&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-jdbc?arch=x86_64&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-jdbc?arch=s390x&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-jdbc?arch=ppc64&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-jdbc?arch=i686&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-devel?arch=x86_64&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-devel?arch=s390x&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-devel?arch=ppc64&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-devel?arch=i686&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-demo?arch=x86_64&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-demo?arch=s390x&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-demo?arch=ppc64&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
pkg:rpm/redhat/java-1.8.0-ibm-demo?arch=i686&distro=redhat-6.10 < 1.8.0.5.40-1jpp.1.el6_10
ID
RHSA-2019:2592
Severity
important
URL
https://access.redhat.com/errata/RHSA-2019:2592
Published
2019-09-03T00:00:00
(5 years ago)
Modified
2019-09-03T00:00:00
(5 years ago)
Rights
Copyright 2019 Red Hat, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/java-1.8.0-ibm?arch=x86_64&distro=redhat-6.10 redhat java-1.8.0-ibm < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 x86_64
Affected pkg:rpm/redhat/java-1.8.0-ibm?arch=s390x&distro=redhat-6.10 redhat java-1.8.0-ibm < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 s390x
Affected pkg:rpm/redhat/java-1.8.0-ibm?arch=ppc64&distro=redhat-6.10 redhat java-1.8.0-ibm < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 ppc64
Affected pkg:rpm/redhat/java-1.8.0-ibm?arch=i686&distro=redhat-6.10 redhat java-1.8.0-ibm < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 i686
Affected pkg:rpm/redhat/java-1.8.0-ibm-src?arch=x86_64&distro=redhat-6.10 redhat java-1.8.0-ibm-src < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 x86_64
Affected pkg:rpm/redhat/java-1.8.0-ibm-src?arch=s390x&distro=redhat-6.10 redhat java-1.8.0-ibm-src < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 s390x
Affected pkg:rpm/redhat/java-1.8.0-ibm-src?arch=ppc64&distro=redhat-6.10 redhat java-1.8.0-ibm-src < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 ppc64
Affected pkg:rpm/redhat/java-1.8.0-ibm-src?arch=i686&distro=redhat-6.10 redhat java-1.8.0-ibm-src < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 i686
Affected pkg:rpm/redhat/java-1.8.0-ibm-plugin?arch=x86_64&distro=redhat-6.10 redhat java-1.8.0-ibm-plugin < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 x86_64
Affected pkg:rpm/redhat/java-1.8.0-ibm-plugin?arch=i686&distro=redhat-6.10 redhat java-1.8.0-ibm-plugin < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 i686
Affected pkg:rpm/redhat/java-1.8.0-ibm-jdbc?arch=x86_64&distro=redhat-6.10 redhat java-1.8.0-ibm-jdbc < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 x86_64
Affected pkg:rpm/redhat/java-1.8.0-ibm-jdbc?arch=s390x&distro=redhat-6.10 redhat java-1.8.0-ibm-jdbc < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 s390x
Affected pkg:rpm/redhat/java-1.8.0-ibm-jdbc?arch=ppc64&distro=redhat-6.10 redhat java-1.8.0-ibm-jdbc < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 ppc64
Affected pkg:rpm/redhat/java-1.8.0-ibm-jdbc?arch=i686&distro=redhat-6.10 redhat java-1.8.0-ibm-jdbc < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 i686
Affected pkg:rpm/redhat/java-1.8.0-ibm-devel?arch=x86_64&distro=redhat-6.10 redhat java-1.8.0-ibm-devel < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 x86_64
Affected pkg:rpm/redhat/java-1.8.0-ibm-devel?arch=s390x&distro=redhat-6.10 redhat java-1.8.0-ibm-devel < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 s390x
Affected pkg:rpm/redhat/java-1.8.0-ibm-devel?arch=ppc64&distro=redhat-6.10 redhat java-1.8.0-ibm-devel < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 ppc64
Affected pkg:rpm/redhat/java-1.8.0-ibm-devel?arch=i686&distro=redhat-6.10 redhat java-1.8.0-ibm-devel < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 i686
Affected pkg:rpm/redhat/java-1.8.0-ibm-demo?arch=x86_64&distro=redhat-6.10 redhat java-1.8.0-ibm-demo < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 x86_64
Affected pkg:rpm/redhat/java-1.8.0-ibm-demo?arch=s390x&distro=redhat-6.10 redhat java-1.8.0-ibm-demo < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 s390x
Affected pkg:rpm/redhat/java-1.8.0-ibm-demo?arch=ppc64&distro=redhat-6.10 redhat java-1.8.0-ibm-demo < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 ppc64
Affected pkg:rpm/redhat/java-1.8.0-ibm-demo?arch=i686&distro=redhat-6.10 redhat java-1.8.0-ibm-demo < 1.8.0.5.40-1jpp.1.el6_10 redhat-6.10 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...