FS#73128 - jdk8-openjdk high security risks

Attached to Project: Arch Linux
Opened by med medin (medmedin) - Thursday, 23 December 2021, 12:53 GMT
Last edited by Antonio Rojas (arojas) - Thursday, 23 December 2021, 20:08 GMT
Task Type Bug Report
Category Packages: Extra
Status Closed
Assigned To No-one
Architecture All
Severity Low
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

jdk8-openjdk is not patched with latest updates which cause high security risk for users that use it. The current version is 8.u292 (from April/2021) while latest is 8.u312 (October/2021).
This task depends upon

Closed by  Antonio Rojas (arojas)
Thursday, 23 December 2021, 20:08 GMT
Reason for closing:  Fixed
Additional comments about closing:  updated
Comment by med medin (medmedin) - Thursday, 23 December 2021, 18:44 GMT
Some of the security risks that need to be patched with updating to new release are :

CVE-2021-2341 (Low)
CVE-2021-2369 (Medium)
CVE-2021-2388 (High)
CVE-2021-35550 (Medium)
CVE-2021-35556 (Medium)
CVE-2021-35559 (Medium)
CVE-2021-35561 (Medium)
CVE-2021-35564 (Medium)
CVE-2021-35565 (Medium)
CVE-2021-35567 (Medium)
CVE-2021-35578 (Medium)
CVE-2021-35586 (Medium)
CVE-2021-35588 (Low)
CVE-2021-35603 (Low)

Loading...