A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
{
"binaries": [
{
"binary_name": "openjdk-9-demo",
"binary_version": "9~b114-0ubuntu1"
},
{
"binary_name": "openjdk-9-jdk",
"binary_version": "9~b114-0ubuntu1"
},
{
"binary_name": "openjdk-9-jdk-headless",
"binary_version": "9~b114-0ubuntu1"
},
{
"binary_name": "openjdk-9-jre",
"binary_version": "9~b114-0ubuntu1"
},
{
"binary_name": "openjdk-9-jre-headless",
"binary_version": "9~b114-0ubuntu1"
},
{
"binary_name": "openjdk-9-source",
"binary_version": "9~b114-0ubuntu1"
}
]
}
{
"binaries": [
{
"binary_name": "openjdk-13-demo",
"binary_version": "13.0.7+5-0ubuntu1~20.04"
},
{
"binary_name": "openjdk-13-jdk",
"binary_version": "13.0.7+5-0ubuntu1~20.04"
},
{
"binary_name": "openjdk-13-jdk-headless",
"binary_version": "13.0.7+5-0ubuntu1~20.04"
},
{
"binary_name": "openjdk-13-jre",
"binary_version": "13.0.7+5-0ubuntu1~20.04"
},
{
"binary_name": "openjdk-13-jre-headless",
"binary_version": "13.0.7+5-0ubuntu1~20.04"
},
{
"binary_name": "openjdk-13-jre-zero",
"binary_version": "13.0.7+5-0ubuntu1~20.04"
},
{
"binary_name": "openjdk-13-source",
"binary_version": "13.0.7+5-0ubuntu1~20.04"
}
]
}
{
"binaries": [
{
"binary_name": "openjdk-16-demo",
"binary_version": "16.0.1+9-1~20.04"
},
{
"binary_name": "openjdk-16-jdk",
"binary_version": "16.0.1+9-1~20.04"
},
{
"binary_name": "openjdk-16-jdk-headless",
"binary_version": "16.0.1+9-1~20.04"
},
{
"binary_name": "openjdk-16-jre",
"binary_version": "16.0.1+9-1~20.04"
},
{
"binary_name": "openjdk-16-jre-headless",
"binary_version": "16.0.1+9-1~20.04"
},
{
"binary_name": "openjdk-16-jre-zero",
"binary_version": "16.0.1+9-1~20.04"
},
{
"binary_name": "openjdk-16-source",
"binary_version": "16.0.1+9-1~20.04"
}
]
}
{
"binaries": [
{
"binary_name": "openjdk-18-demo",
"binary_version": "18.0.2+9-2~22.04"
},
{
"binary_name": "openjdk-18-jdk",
"binary_version": "18.0.2+9-2~22.04"
},
{
"binary_name": "openjdk-18-jdk-headless",
"binary_version": "18.0.2+9-2~22.04"
},
{
"binary_name": "openjdk-18-jre",
"binary_version": "18.0.2+9-2~22.04"
},
{
"binary_name": "openjdk-18-jre-headless",
"binary_version": "18.0.2+9-2~22.04"
},
{
"binary_name": "openjdk-18-jre-zero",
"binary_version": "18.0.2+9-2~22.04"
},
{
"binary_name": "openjdk-18-source",
"binary_version": "18.0.2+9-2~22.04"
}
]
}
{
"binaries": [
{
"binary_name": "openjdk-19-demo",
"binary_version": "19.0.2+7-0ubuntu3~22.04"
},
{
"binary_name": "openjdk-19-jdk",
"binary_version": "19.0.2+7-0ubuntu3~22.04"
},
{
"binary_name": "openjdk-19-jdk-headless",
"binary_version": "19.0.2+7-0ubuntu3~22.04"
},
{
"binary_name": "openjdk-19-jre",
"binary_version": "19.0.2+7-0ubuntu3~22.04"
},
{
"binary_name": "openjdk-19-jre-headless",
"binary_version": "19.0.2+7-0ubuntu3~22.04"
},
{
"binary_name": "openjdk-19-jre-zero",
"binary_version": "19.0.2+7-0ubuntu3~22.04"
},
{
"binary_name": "openjdk-19-source",
"binary_version": "19.0.2+7-0ubuntu3~22.04"
}
]
}