RHSA-2023:4210MediumCVSS 7.5
Red Hat Security Advisory: OpenJDK 17.0.8 Security Update for Portable Linux Builds
🔗 CVE IDs covered (7)
📋 Description
CVE-2023-22006 — OpenJDK: HTTP client insufficient file name validation (8302475) CVE-2023-22036 — OpenJDK: ZIP file parsing infinite loop (8302483) CVE-2023-22041 — OpenJDK: weakness in AES implementation (8308682) CVE-2023-22044 — OpenJDK: modulo operator array indexing issue (8304460) CVE-2023-22045 — OpenJDK: array indexing integer overflow issue (8304468) CVE-2023-22049 — OpenJDK: improper handling of slash characters in URI-to-path conversion (8305312) CVE-2023-25193 — harfbuzz: allows attackers to trigger O(n^2) growth via consecutive marks
🎯 Affected products1
- Red Hat Build of OpenJDK 17.0.8
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2023:4210
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2167254
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221619
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221626
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221634
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221642
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221645
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2221647
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2223207
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_4210.json