USN-5719-1

Source
https://ubuntu.com/security/notices/USN-5719-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-5719-1.json
Related
Published
2022-11-09T11:20:53.874698Z
Modified
2022-11-09T11:20:53.874698Z
Summary
openjdk-8, openjdk-lts, openjdk-17, openjdk-19 vulnerabilities
Details

It was discovered that OpenJDK incorrectly handled long client hostnames. An attacker could possibly use this issue to cause the corruption of sensitive information. (CVE-2022-21619)

It was discovered that OpenJDK incorrectly randomized DNS port numbers. A remote attacker could possibly use this issue to perform spoofing attacks. (CVE-2022-21624)

It was discovered that OpenJDK did not limit the number of connections accepted from HTTP clients. An attacker could possibly use this issue to cause a denial of service. (CVE-2022-21628)

It was discovered that OpenJDK incorrectly handled X.509 certificates. An attacker could possibly use this issue to cause a denial of service. This issue only affected OpenJDK 8 and OpenJDK 11. (CVE-2022-21626)

It was discovered that OpenJDK incorrectly handled cached server connections. An attacker could possibly use this issue to perform spoofing attacks. This issue only affected OpenJDK 11, OpenJDK 17 and OpenJDK 19. (CVE-2022-39399)

It was discovered that OpenJDK incorrectly handled byte conversions. An attacker could possibly use this issue to obtain sensitive information. This issue only affected OpenJDK 11, OpenJDK 17 and OpenJDK 19. (CVE-2022-21618)

References

Affected packages

Ubuntu:22.04:LTS / openjdk-17

Package

Name
openjdk-17

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
17.0.5+8-2ubuntu1~22.04

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "openjdk-17-jdk": "17.0.5+8-2ubuntu1~22.04",
            "openjdk-17-jdk-headless": "17.0.5+8-2ubuntu1~22.04",
            "openjdk-17-demo": "17.0.5+8-2ubuntu1~22.04",
            "openjdk-17-jre": "17.0.5+8-2ubuntu1~22.04",
            "openjdk-17-source": "17.0.5+8-2ubuntu1~22.04",
            "openjdk-17-doc": "17.0.5+8-2ubuntu1~22.04",
            "openjdk-17-jre-zero": "17.0.5+8-2ubuntu1~22.04",
            "openjdk-17-jre-headless": "17.0.5+8-2ubuntu1~22.04"
        }
    ]
}

Ubuntu:22.04:LTS / openjdk-19

Package

Name
openjdk-19

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
19.0.1+10-1ubuntu1~22.04

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "openjdk-19-jre-zero": "19.0.1+10-1ubuntu1~22.04",
            "openjdk-19-jre-headless": "19.0.1+10-1ubuntu1~22.04",
            "openjdk-19-jdk": "19.0.1+10-1ubuntu1~22.04",
            "openjdk-19-demo": "19.0.1+10-1ubuntu1~22.04",
            "openjdk-19-doc": "19.0.1+10-1ubuntu1~22.04",
            "openjdk-19-source": "19.0.1+10-1ubuntu1~22.04",
            "openjdk-19-jre": "19.0.1+10-1ubuntu1~22.04",
            "openjdk-19-jdk-headless": "19.0.1+10-1ubuntu1~22.04"
        }
    ]
}

Ubuntu:22.04:LTS / openjdk-lts

Package

Name
openjdk-lts

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
11.0.17+8-1ubuntu2~22.04

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "openjdk-11-jre-zero": "11.0.17+8-1ubuntu2~22.04",
            "openjdk-11-demo": "11.0.17+8-1ubuntu2~22.04",
            "openjdk-11-source": "11.0.17+8-1ubuntu2~22.04",
            "openjdk-11-jdk": "11.0.17+8-1ubuntu2~22.04",
            "openjdk-11-doc": "11.0.17+8-1ubuntu2~22.04",
            "openjdk-11-jdk-headless": "11.0.17+8-1ubuntu2~22.04",
            "openjdk-11-jre": "11.0.17+8-1ubuntu2~22.04",
            "openjdk-11-jre-headless": "11.0.17+8-1ubuntu2~22.04"
        }
    ]
}

Ubuntu:22.04:LTS / openjdk-8

Package

Name
openjdk-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
8u352-ga-1~22.04

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "openjdk-8-jdk-headless": "8u352-ga-1~22.04",
            "openjdk-8-jre-zero": "8u352-ga-1~22.04",
            "openjdk-8-demo": "8u352-ga-1~22.04",
            "openjdk-8-jre-headless": "8u352-ga-1~22.04",
            "openjdk-8-source": "8u352-ga-1~22.04",
            "openjdk-8-jdk": "8u352-ga-1~22.04",
            "openjdk-8-jre": "8u352-ga-1~22.04",
            "openjdk-8-doc": "8u352-ga-1~22.04"
        }
    ]
}

Ubuntu:18.04:LTS / openjdk-17

Package

Name
openjdk-17

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
17.0.5+8-2ubuntu1~18.04

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "openjdk-17-jdk": "17.0.5+8-2ubuntu1~18.04",
            "openjdk-17-jdk-headless": "17.0.5+8-2ubuntu1~18.04",
            "openjdk-17-demo": "17.0.5+8-2ubuntu1~18.04",
            "openjdk-17-jre": "17.0.5+8-2ubuntu1~18.04",
            "openjdk-17-source": "17.0.5+8-2ubuntu1~18.04",
            "openjdk-17-doc": "17.0.5+8-2ubuntu1~18.04",
            "openjdk-17-jre-zero": "17.0.5+8-2ubuntu1~18.04",
            "openjdk-17-jre-headless": "17.0.5+8-2ubuntu1~18.04"
        }
    ]
}

Ubuntu:18.04:LTS / openjdk-lts

Package

Name
openjdk-lts

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
11.0.17+8-1ubuntu2~18.04

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "openjdk-11-jre-zero": "11.0.17+8-1ubuntu2~18.04",
            "openjdk-11-demo": "11.0.17+8-1ubuntu2~18.04",
            "openjdk-11-source": "11.0.17+8-1ubuntu2~18.04",
            "openjdk-11-jdk": "11.0.17+8-1ubuntu2~18.04",
            "openjdk-11-doc": "11.0.17+8-1ubuntu2~18.04",
            "openjdk-11-jdk-headless": "11.0.17+8-1ubuntu2~18.04",
            "openjdk-11-jre": "11.0.17+8-1ubuntu2~18.04",
            "openjdk-11-jre-headless": "11.0.17+8-1ubuntu2~18.04"
        }
    ]
}

Ubuntu:18.04:LTS / openjdk-8

Package

Name
openjdk-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
8u352-ga-1~18.04

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "openjdk-8-jdk-headless": "8u352-ga-1~18.04",
            "openjdk-8-jre-zero": "8u352-ga-1~18.04",
            "openjdk-8-demo": "8u352-ga-1~18.04",
            "openjdk-8-jre-headless": "8u352-ga-1~18.04",
            "openjdk-8-source": "8u352-ga-1~18.04",
            "openjdk-8-jdk": "8u352-ga-1~18.04",
            "openjdk-8-jre": "8u352-ga-1~18.04",
            "openjdk-8-doc": "8u352-ga-1~18.04"
        }
    ]
}

Ubuntu:20.04:LTS / openjdk-17

Package

Name
openjdk-17

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
17.0.5+8-2ubuntu1~20.04

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "openjdk-17-jdk": "17.0.5+8-2ubuntu1~20.04",
            "openjdk-17-jdk-headless": "17.0.5+8-2ubuntu1~20.04",
            "openjdk-17-demo": "17.0.5+8-2ubuntu1~20.04",
            "openjdk-17-jre": "17.0.5+8-2ubuntu1~20.04",
            "openjdk-17-source": "17.0.5+8-2ubuntu1~20.04",
            "openjdk-17-doc": "17.0.5+8-2ubuntu1~20.04",
            "openjdk-17-jre-zero": "17.0.5+8-2ubuntu1~20.04",
            "openjdk-17-jre-headless": "17.0.5+8-2ubuntu1~20.04"
        }
    ]
}

Ubuntu:20.04:LTS / openjdk-lts

Package

Name
openjdk-lts

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
11.0.17+8-1ubuntu2~20.04

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "openjdk-11-jre-zero": "11.0.17+8-1ubuntu2~20.04",
            "openjdk-11-demo": "11.0.17+8-1ubuntu2~20.04",
            "openjdk-11-source": "11.0.17+8-1ubuntu2~20.04",
            "openjdk-11-jdk": "11.0.17+8-1ubuntu2~20.04",
            "openjdk-11-doc": "11.0.17+8-1ubuntu2~20.04",
            "openjdk-11-jdk-headless": "11.0.17+8-1ubuntu2~20.04",
            "openjdk-11-jre": "11.0.17+8-1ubuntu2~20.04",
            "openjdk-11-jre-headless": "11.0.17+8-1ubuntu2~20.04"
        }
    ]
}

Ubuntu:20.04:LTS / openjdk-8

Package

Name
openjdk-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
8u352-ga-1~20.04

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "openjdk-8-jdk-headless": "8u352-ga-1~20.04",
            "openjdk-8-jre-zero": "8u352-ga-1~20.04",
            "openjdk-8-demo": "8u352-ga-1~20.04",
            "openjdk-8-jre-headless": "8u352-ga-1~20.04",
            "openjdk-8-source": "8u352-ga-1~20.04",
            "openjdk-8-jdk": "8u352-ga-1~20.04",
            "openjdk-8-jre": "8u352-ga-1~20.04",
            "openjdk-8-doc": "8u352-ga-1~20.04"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / openjdk-8

Package

Name
openjdk-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
8u352-ga-1~16.04

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "openjdk-8-jre-jamvm": "8u352-ga-1~16.04",
            "openjdk-8-jdk-headless": "8u352-ga-1~16.04",
            "openjdk-8-jre-zero": "8u352-ga-1~16.04",
            "openjdk-8-demo": "8u352-ga-1~16.04",
            "openjdk-8-jre-headless": "8u352-ga-1~16.04",
            "openjdk-8-source": "8u352-ga-1~16.04",
            "openjdk-8-jdk": "8u352-ga-1~16.04",
            "openjdk-8-jre": "8u352-ga-1~16.04",
            "openjdk-8-doc": "8u352-ga-1~16.04"
        }
    ]
}