File _patchinfo of Package patchinfo.36365
<patchinfo incident="36365"> <issue tracker="cve" id="2024-21145"/> <issue tracker="cve" id="2024-21210"/> <issue tracker="cve" id="2024-21217"/> <issue tracker="cve" id="2024-21208"/> <issue tracker="cve" id="2024-21235"/> <issue tracker="bnc" id="1231711">VUL-0: CVE-2024-21210: java-*-openjdk,java-*-ibm: component: Hotspot</issue> <issue tracker="bnc" id="1228051">VUL-0: CVE-2024-21145: java-*-openjdk,java-*-ibm: OpenJDK: Out-of-bounds access in 2D image handling</issue> <issue tracker="bnc" id="1231716">VUL-0: CVE-2024-21217: java-*-openjdk,java-*-ibm: partial DoS in component Serialization</issue> <issue tracker="bnc" id="1231702">VUL-0: CVE-2024-21208: java-*-openjdk,java-*-ibm: component: Networking</issue> <issue tracker="bnc" id="1231719">VUL-0: CVE-2024-21235: java-*-openjdk,java-*-ibm: unauthorized read/write access to data in component Hotspot</issue> <packager>fstrba</packager> <rating>moderate</rating> <category>security</category> <summary>Security update for java-1_8_0-openjdk</summary> <description>This update for java-1_8_0-openjdk fixes the following issues: Update to version jdk8u432 (icedtea-3.33.0): - CVE-2024-21208: Enhance HTTP client (bsc#1231702). - CVE-2024-21210: Improve handling of vectorization (bsc#1231711). - CVE-2024-21217: Improve deserialization support (bsc#1231716). - CVE-2024-21235: Improve graph optimizations (bsc#1231719). - CVE-2024-21145: Improve 2D image (bsc#1228051). </description> </patchinfo>