{"id":21386,"date":"2022-03-07T19:49:05","date_gmt":"2022-03-07T16:49:05","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/166224\/USN-5313-1.txt"},"modified":"2022-03-08T09:08:15","modified_gmt":"2022-03-08T05:38:15","slug":"ubuntu-security-notice-usn-5313-1","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/ubuntu-security-notice-usn-5313-1\/","title":{"rendered":"Ubuntu Security Notice USN-5313-1"},"content":{"rendered":"<p dir=\"ltr\">==========================================================================<br \/>\nUbuntu Security Notice USN-5313-1<br \/>\nMarch 07, 2022<\/p>\n<p dir=\"ltr\">openjdk-lts, openjdk-17 vulnerabilities<br \/>\n==========================================================================<\/p>\n<p dir=\"ltr\">A security issue affects these releases of Ubuntu and its derivatives:<\/p>\n<p dir=\"ltr\">&#8211; Ubuntu 21.10<br \/>\n&#8211; Ubuntu 20.04 LTS<br \/>\n&#8211; Ubuntu 18.04 LTS<\/p>\n<p dir=\"ltr\">Summary:<\/p>\n<p dir=\"ltr\">Several security issues were fixed in OpenJDK.<\/p>\n<p dir=\"ltr\">Software Description:<br \/>\n&#8211; openjdk-17: Open Source Java implementation<br \/>\n&#8211; openjdk-lts: Open Source Java implementation<\/p>\n<p dir=\"ltr\">Details:<\/p>\n<p dir=\"ltr\">It was discovered that OpenJDK incorrectly handled deserialization filters.<br \/>\nAn attacker could possibly use this issue to insert, delete or obtain<br \/>\nsensitive information. (CVE-2022-21248)<\/p>\n<p dir=\"ltr\">It was discovered that OpenJDK incorrectly read uncompressed TIFF files.<br \/>\nAn attacker could possibly use this issue to cause a denial of service via<br \/>\na specially crafted TIFF file. (CVE-2022-21277)<\/p>\n<p dir=\"ltr\">Jonni Passki discovered that OpenJDK incorrectly verified access<br \/>\nrestrictions when performing URI resolution. An attacker could possibly<br \/>\nuse this issue to obtain sensitive information. (CVE-2022-21282)<\/p>\n<p dir=\"ltr\">It was discovered that OpenJDK incorrectly handled certain regular<br \/>\nexpressions in the Pattern class implementation. An attacker could<br \/>\npossibly use this issue to cause a denial of service. (CVE-2022-21283)<\/p>\n<p dir=\"ltr\">It was discovered that OpenJDK incorrectly handled specially crafted Java<br \/>\nclass files. An attacker could possibly use this issue to cause a denial<br \/>\nof service. (CVE-2022-21291)<\/p>\n<p dir=\"ltr\">Markus Loewe discovered that OpenJDK incorrectly validated attributes<br \/>\nduring object deserialization. An attacker could possibly use this issue<br \/>\nto cause a denial of service. (CVE-2022-21293, CVE-2022-21294)<\/p>\n<p dir=\"ltr\">Dan Rabe discovered that OpenJDK incorrectly verified access permissions<br \/>\nin the JAXP component. An attacker could possibly use this to specially<br \/>\ncraft an XML file to obtain sensitive information. (CVE-2022-21296)<\/p>\n<p dir=\"ltr\">It was discovered that OpenJDK incorrectly handled XML entities. An<br \/>\nattacker could use this to specially craft an XML file that, when parsed,<br \/>\nwould possibly cause a denial of service. (CVE-2022-21299)<\/p>\n<p dir=\"ltr\">Zhiqiang Zang discovered that OpenJDK incorrectly handled array indexes.<br \/>\nAn attacker could possibly use this issue to obtain sensitive information.<br \/>\n(CVE-2022-21305)<\/p>\n<p dir=\"ltr\">It was discovered that OpenJDK incorrectly read very long attributes<br \/>\nvalues in JAR file manifests. An attacker could possibly use this to<br \/>\nspecially craft JAR file to cause a denial of service. (CVE-2022-21340)<\/p>\n<p dir=\"ltr\">It was discovered that OpenJDK incorrectly validated input from serialized<br \/>\nstreams. An attacker cold possibly use this issue to bypass sandbox<br \/>\nrestrictions. (CVE-2022-21341)<\/p>\n<p dir=\"ltr\">Fabian Meumertzheim discovered that OpenJDK incorrectly handled certain<br \/>\nspecially crafted BMP or TIFF files. An attacker could possibly use this<br \/>\nto cause a denial of service. (CVE-2022-21360, CVE-2022-21366)<\/p>\n<p dir=\"ltr\">It was discovered that an integer overflow could be triggered in OpenJDK<br \/>\nBMPImageReader class implementation. An attacker could possibly use this<br \/>\nto specially craft a BMP file to cause a denial of service.<br \/>\n(CVE-2022-21365)<\/p>\n<p dir=\"ltr\">Update instructions:<\/p>\n<p dir=\"ltr\">The problem can be corrected by updating your system to the following<br \/>\npackage versions:<\/p>\n<p dir=\"ltr\">Ubuntu 21.10:<br \/>\nopenjdk-11-jdk 11.0.14+9-0ubuntu2~22.10<br \/>\nopenjdk-11-jre 11.0.14+9-0ubuntu2~22.10<br \/>\nopenjdk-11-jre-headless 11.0.14+9-0ubuntu2~22.10<br \/>\nopenjdk-11-jre-zero 11.0.14+9-0ubuntu2~22.10<br \/>\nopenjdk-17-jdk 17.0.2+8-1~22.10<br \/>\nopenjdk-17-jre 17.0.2+8-1~22.10<br \/>\nopenjdk-17-jre-headless 17.0.2+8-1~22.10<br \/>\nopenjdk-17-jre-zero 17.0.2+8-1~22.10<\/p>\n<p dir=\"ltr\">Ubuntu 20.04 LTS:<br \/>\nopenjdk-11-jdk 11.0.14+9-0ubuntu2~20.04<br \/>\nopenjdk-11-jre 11.0.14+9-0ubuntu2~20.04<br \/>\nopenjdk-11-jre-headless 11.0.14+9-0ubuntu2~20.04<br \/>\nopenjdk-11-jre-zero 11.0.14+9-0ubuntu2~20.04<br \/>\nopenjdk-17-jdk 17.0.2+8-1~20.04<br \/>\nopenjdk-17-jre 17.0.2+8-1~20.04<br \/>\nopenjdk-17-jre-headless 17.0.2+8-1~20.04<br \/>\nopenjdk-17-jre-zero 17.0.2+8-1~20.04<\/p>\n<p dir=\"ltr\">Ubuntu 18.04 LTS:<br \/>\nopenjdk-11-jdk 11.0.14+9-0ubuntu2~18.04<br \/>\nopenjdk-11-jre 11.0.14+9-0ubuntu2~18.04<br \/>\nopenjdk-11-jre-headless 11.0.14+9-0ubuntu2~18.04<br \/>\nopenjdk-11-jre-zero 11.0.14+9-0ubuntu2~18.04<br \/>\nopenjdk-17-jdk 17.0.2+8-1~18.04<br \/>\nopenjdk-17-jre 17.0.2+8-1~18.04<br \/>\nopenjdk-17-jre-headless 17.0.2+8-1~18.04<br \/>\nopenjdk-17-jre-zero 17.0.2+8-1~18.04<\/p>\n<p dir=\"ltr\">This update uses a new upstream release, which includes additional bug<br \/>\nfixes. After a standard system update you need to restart any Java<br \/>\napplications or applets to make all the necessary changes.<\/p>\n<p dir=\"ltr\">References:<br \/>\nhttps:\/\/ubuntu.com\/security\/notices\/USN-5313-1<br \/>\nCVE-2022-21248, CVE-2022-21277, CVE-2022-21282, CVE-2022-21283,<br \/>\nCVE-2022-21291, CVE-2022-21293, CVE-2022-21294, CVE-2022-21296,<br \/>\nCVE-2022-21299, CVE-2022-21305, CVE-2022-21340, CVE-2022-21341,<br \/>\nCVE-2022-21360, CVE-2022-21365, CVE-2022-21366<\/p>\n<p dir=\"ltr\">Package Information:<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/openjdk-17\/17.0.2+8-1~22.10<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/openjdk-lts\/11.0.14+9-0ubuntu2~22.10<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/openjdk-17\/17.0.2+8-1~20.04<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/openjdk-lts\/11.0.14+9-0ubuntu2~20.04<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/openjdk-17\/17.0.2+8-1~18.04<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/openjdk-lts\/11.0.14+9-0ubuntu2~18.04<\/p>\n","protected":false},"excerpt":{"rendered":"<p>========================================================================== Ubuntu Security Notice USN-5313-1 March 07, 2022 openjdk-lts, openjdk-17 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: &#8211; Ubuntu 21.10 &#8211; Ubuntu 20.04 LTS &#8211; Ubuntu 18.04 LTS Summary: Several security issues were fixed in OpenJDK. Software Description: &#8211; openjdk-17: Open Source Java implementation &#8211; openjdk-lts: Open Source Java &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-21386","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/21386","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=21386"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/21386\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=21386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=21386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=21386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}