Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 5335-1] openjdk-17 security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 5335-1] openjdk-17 security update


Chronologisch Thread  
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 5335-1] openjdk-17 security update
  • Date: Wed, 1 Feb 2023 18:32:12 +0000
  • Authentication-results: mail.piratenpartei.de; dkim=none; spf=none (mail.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 2001:41b8:202:deb:216:36ff:fe40:4002) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
  • List-archive: https://lists.debian.org/msgid-search/Y9qwLAJPHvU+DZtr AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From:Date :Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=+dMS/QZC3JbcefCI0qRj541Dr+U3twx4oP68NL78dks=; b=SZ dOvOUjL2Ek6l9Mx6X1vQPct0PhTCJQmoiWYoCTWrZkHUva2WiASlRHxJzZ7WLy4Bp9vwXnxstsHCo ITifSfwvRD7RgEP2TQc7YT9eou7/t5zMe8Qnj8UTCwyfW24fpFtWlMttQcDjnW8arTHbcSiYWeHHE MlpNhy+CDUdCqgN9TwBuKQa9DOSOU5E7GGk06cxkG5A46d4K66LnDWdLCXugIgjuI+p8UaaeNN+ER ckipJ4xokJb8UCKmLdUsx6y1cioTlyW74bE/dukpn58Fh5V9KfssiXtml6QTE5fDrGnkujpK3Ycyf 5M5YNgtWI7qjc42yI5CZD37ykK67/3jg==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Wed, 1 Feb 2023 18:32:36 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <HlZHEfitjEF.A.CsG.EBr2jB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-5335-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
February 01, 2023 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : openjdk-17
CVE ID : CVE-2022-21618 CVE-2022-21619 CVE-2022-21624 CVE-2022-21628
CVE-2022-39399 CVE-2023-21835 CVE-2023-21843

Several vulnerabilities have been discovered in the OpenJDK Java runtime,
which may result in denial of service or spoofing.

For the stable distribution (bullseye), these problems have been fixed in
version 17.0.6+10-1~deb11u1.

We recommend that you upgrade your openjdk-17 packages.

For the detailed security status of openjdk-17 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/openjdk-17

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmParr8ACgkQEMKTtsN8
TjaUew/9Fpsfn3GMMnCaheFv/IAODAauovmI71hUQpohxEX5eL17mLWX4s5L0qtu
HHHlexE4EtWNRk2KUtsm5oroX95mseqNhXObvX7dho0pGn8eM0N9FuJ3eXdWMxxP
MW8Q+MADyDHuWB5/Fb6a16NpCIqzeUgS2CEMaM+6BCp2O2Mz+O0EfH/3MC9GW3z7
sP+IUD3nm0+03J00CgZfEvRN2g1NElIerCQiSMeNC7T21V4Lz7MnVNCV1jyTvdm9
IV5HXuVdEjeSbdC2sJbnF3geGDV5cLBcY7Il8JbcT/ADCUGkxM8wnilsiRrDj+e0
gTuturVqUxLvjjxjpMNdLZrmv3WUMuBgFNkVpriDGXEjalsCX2yfYVQUyNGUZHCC
o0VEuPjEKFQh8anUiugwF4ZqMfosbZcbrT7eTWFsJlAMTiBi+k8Qs3K9q9XeIW8Y
LnMCiaTLzC+3ZL65J0r2E+CiGrie/DGaWxLaXVxt2/Qux3MOf5mKoVZSHEl7jKey
sIIZoav9p8/Rj/3DmMLJi+visUH/aptKzbgXEAIAjSMs9pXtgu4PYZ5faAecRC9K
G6edx+RrdXMS7nuuzH+rlCkGRJ9oszyHlcpV0cFI4/ss5ljY9rtrw7cs3qN2kZz5
RrtXMAQc0xXLTZJTozNsqf7ael4mWfUoc809BMRobJ1m1bBTWTA=
=Pibq
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 5335-1] openjdk-17 security update, Moritz Muehlenhoff, 01.02.2023

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang