You are here
Home > Preporuke > Sigurnosna nadogradnja za programski paket openjdk-7

Sigurnosna nadogradnja za programski paket openjdk-7

==========================================================================
Ubuntu Security Notice USN-2319-2
August 26, 2014

openjdk-7 regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 14.04 LTS

Summary:

USN-2319-1 introduced a regression in OpenJDK 7.

Software Description:
– openjdk-7: Open Source Java implementation

Details:

USN-2319-1 fixed vulnerabilities in OpenJDK 7. Due to an upstream
regression, verifying of the init method call would fail when it was done
from inside a branch when stack frames are activated. This update fixes the
problem.

We apologize for the inconvenience.

Original advisory details:

Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure, data integrity and availability. An attacker could
exploit these to cause a denial of service or expose sensitive data over
the network. (CVE-2014-2483, CVE-2014-2490, CVE-2014-4216, CVE-2014-4219,
CVE-2014-4223, CVE-2014-4262)

Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure and data integrity. An attacker could exploit these
to expose sensitive data over the network. (CVE-2014-4209, CVE-2014-4244,
CVE-2014-4263)

Two vulnerabilities were discovered in the OpenJDK JRE related to data
integrity. (CVE-2014-4218, CVE-2014-4266)

A vulnerability was discovered in the OpenJDK JRE related to availability.
An attacker could exploit this to cause a denial of service.
(CVE-2014-4264)

Several vulnerabilities were discovered in the OpenJDK JRE related to
information disclosure. An attacker could exploit these to expose sensitive
data over the network. (CVE-2014-4221, CVE-2014-4252, CVE-2014-4268)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 14.04 LTS:
icedtea-7-jre-jamvm 7u65-2.5.1-4ubuntu1~0.14.04.2
openjdk-7-jre 7u65-2.5.1-4ubuntu1~0.14.04.2
openjdk-7-jre-headless 7u65-2.5.1-4ubuntu1~0.14.04.2
openjdk-7-jre-lib 7u65-2.5.1-4ubuntu1~0.14.04.2
openjdk-7-jre-zero 7u65-2.5.1-4ubuntu1~0.14.04.2

After a standard system update you need to restart any Java applications
to make all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-2319-2
http://www.ubuntu.com/usn/usn-2319-1
https://launchpad.net/bugs/1360392

Package Information:
https://launchpad.net/ubuntu/+source/openjdk-7/7u65-2.5.1-4ubuntu1~0.14.04.2

—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBCgAGBQJT+9zpAAoJEFHb3FjMVZVzWaoQAJ8ttlOgc+Py1Rn5C8P+qLFe
IednJXfi0ML805pGIFfJsDOyAPxg6muVyaP6RPjfoqxfdVzU4GJE8nCY4LbESDGC
CS1ZYfj659fM+iH48IM15mPR508fIwtTDQmEVwWD7tWYatpxopGsBQuQ/79fMZBP
bLtA5aICMoBjpx2NKGUPcHEtjme0/osOOy82EHVRByCS005Fi0wk0oP8ROUqiW/H
WEOPHXvK3eNluTrkdeXPwJn6tx3B00GbnwaZDb3haPhlvBrsrbO4d92L6B87lV08
YzhKFhivDVqTHWCloyB8k7FyVy9XxQ7m5IFBakWMaKu1P8oeUdP5NafN1pHElBi4
pNHn4TPJtaTO/T7sc+NQwdKBMm9bv1br9LB1o+O8oTYzowrQIrM1i7vgJfXL33My
+nFu8bttRA89hvmSzD3AAjtLyaiDzpRVE8ABY211E4EMWaxy4w1Qb46TJNtakGQQ
5O+r3Dt5mEyLtQIbHq1BvezBoYpkEBDPtmEaec3BedZbPMS5iInke1rkBONxJpms
TY8vb7rODLrBaU3HxuOxhT8mhZreZvBmJR725XsITjvyoP9BZgVVjpH3dEia8Crq
KdxWtGdpXR7RmkQYH5nvU0IRxfqgDzhH9K7i4JU5B8r38TfmLTMEfz3cNUFtONLt
eo1GtfMDXvFDaHZ28pDO
=Da1g
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostatak programskog paketa mod_wsgi

Otkriven je sigurnosni nedostatak u programskom paketu mod_wsgi za operacijski sustav Red Hat. Otkriveni nedostatak potencijalnim napadačima omogućuje stjecanje povećanih...

Close