File _patchinfo of Package patchinfo.36682
<patchinfo incident="36682">
<issue tracker="bnc" id="1231716">VUL-0: CVE-2024-21217: java-*-openjdk,java-*-ibm: partial DoS in component Serialization</issue>
<issue tracker="bnc" id="1231702">VUL-0: CVE-2024-21208: java-*-openjdk,java-*-ibm: component: Networking</issue>
<issue tracker="bnc" id="1231719">VUL-0: CVE-2024-21235: java-*-openjdk,java-*-ibm: unauthorized read/write access to data in component Hotspot</issue>
<issue tracker="bnc" id="1225470">VUL-0: CVE-2024-3933: java-10-openjdk,java-11-openjdk,java-17-openjdk,java-1_7_0-openjdk,java-1_8_0-ibm,java-1_8_0-openj9,java-1_8_0-openjdk,java-21-openjdk,java-9-openjdk: In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when run ...</issue>
<issue tracker="bnc" id="1231711">VUL-0: CVE-2024-21210: java-*-openjdk,java-*-ibm: component: Hotspot</issue>
<issue tracker="bnc" id="1232064">VUL-0: java-1_8_0-ibm: Oracle October 15 2024 CPU</issue>
<issue tracker="cve" id="2024-21208"/>
<issue tracker="cve" id="2024-21217"/>
<issue tracker="cve" id="2024-3933"/>
<issue tracker="cve" id="2024-21210"/>
<issue tracker="cve" id="2024-21235"/>
<packager>pmonrealgonzalez</packager>
<rating>moderate</rating>
<category>security</category>
<summary>Security update for java-1_8_0-ibm</summary>
<description>This update for java-1_8_0-ibm fixes the following issues:
Updated to Java 8.0 Service Refresh 8 Fix Pack 35 with Oracle October 15 2024 CPU (bsc#1232064):
- CVE-2024-21208: Fixed partial DoS in component Networking (bsc#1231702,JDK-8328286)
- CVE-2024-21210: Fixed unauthorized update, insert or delete access to some of Oracle Java SE accessible data in component Hotspot (bsc#1231711,JDK-8328544)
- CVE-2024-21217: Fixed partial DoS in component Serialization (bsc#1231716,JDK-8331446)
- CVE-2024-21235: Fixed unauthorized read/write access to data in component Hotspot (bsc#1231719,JDK-8332644)
Other issues fixed in past releases:
- CVE-2024-3933: Fixed evaluate constant byteLenNode of arrayCopyChild (bsc#1225470)</description>
</patchinfo>