CLSA-2024-1732194412

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1732194412.json
JSON Data
https://api.osv.dev/v1/vulns/CLSA-2024-1732194412
Upstream
Published
2024-11-21T13:07:03Z
Modified
2026-06-04T10:03:53.838395198Z
Summary
Fix of 14 CVEs
Details
  • Update to 8u432-ga fixing a number of CVEs
    • CVE-2024-21131: UTF8 size overflow
    • CVE-2024-21138: infinite loop vunlerability in SymbolTable
    • CVE-2024-21140: int overflow/underflow in Range Check Elimination
    • CVE-2024-21144: invalid header validation leads to Pack200 excessive loading time
    • CVE-2024-21145: out-of-bounds access in MaskFill
    • CVE-2024-21147: out-of-bounds array index in Range Check Elimination
    • CVE-2024-21208: improper handling of maxHeaderSize in HTTP client
    • CVE-2024-21210: integer overflow in array indexing in SuperWord
    • CVE-2024-21217: out-of-memory because of unbounded allocation in MessageFormat
    • CVE-2024-21235: incorrect range check because of integer conversion error in LoopNode
  • Update patches
    • debian/patches/zero-sh.diff
  • Remove patches that became part of the update
    • debian/patches/CVE-2024-21011.patch
    • debian/patches/CVE-2024-21068.patch
    • debian/patches/CVE-2024-21085.patch
    • debian/patches/CVE-2024-21094.patch
References

Affected packages

TuxCare:Ubuntu:18.04
openjdk-8-demo

Package

Name
openjdk-8-demo
Purl
pkg:deb/tuxcare/openjdk-8-demo?distro=ubuntu-18.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8u432-ga-0ubuntu1~18.04+tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1732194412.json"
openjdk-8-doc

Package

Name
openjdk-8-doc
Purl
pkg:deb/tuxcare/openjdk-8-doc?distro=ubuntu-18.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8u432-ga-0ubuntu1~18.04+tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1732194412.json"
openjdk-8-jdk

Package

Name
openjdk-8-jdk
Purl
pkg:deb/tuxcare/openjdk-8-jdk?distro=ubuntu-18.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8u432-ga-0ubuntu1~18.04+tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1732194412.json"
openjdk-8-jdk-headless

Package

Name
openjdk-8-jdk-headless
Purl
pkg:deb/tuxcare/openjdk-8-jdk-headless?distro=ubuntu-18.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8u432-ga-0ubuntu1~18.04+tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1732194412.json"
openjdk-8-jre

Package

Name
openjdk-8-jre
Purl
pkg:deb/tuxcare/openjdk-8-jre?distro=ubuntu-18.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8u432-ga-0ubuntu1~18.04+tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1732194412.json"
openjdk-8-jre-headless

Package

Name
openjdk-8-jre-headless
Purl
pkg:deb/tuxcare/openjdk-8-jre-headless?distro=ubuntu-18.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8u432-ga-0ubuntu1~18.04+tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1732194412.json"
openjdk-8-jre-zero

Package

Name
openjdk-8-jre-zero
Purl
pkg:deb/tuxcare/openjdk-8-jre-zero?distro=ubuntu-18.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8u432-ga-0ubuntu1~18.04+tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1732194412.json"
openjdk-8-source

Package

Name
openjdk-8-source
Purl
pkg:deb/tuxcare/openjdk-8-source?distro=ubuntu-18.04

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
8u432-ga-0ubuntu1~18.04+tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1732194412.json"