RedHatÇå¾²¸üÐÂÐÞ¸´OpenJDK1.8.0°æ±¾Îó²î
2018-01-19
RedHatÐû²¼Çå¾²²¹¶¡Í¨¸æ£¬ÐÞ¸´Á˶à¸öjava-1.8.0-openjdkµÄÇå¾²ÎÊÌâ¡£
Ïà¹ØÁ´½Ó£º
https://access.redhat.com/errata/RHSA-2018:0095
Îó²î¸ÅÊö
? ÔÚOpenJDKµÄHotspotºÍAWT×é¼þÖз¢Ã÷Á˶à¸öȱÏÝ¡£²»¿ÉÐŵÄJavaÓ¦ÓóÌÐò»òС³ÌÐò¿ÉÒÔʹÓÃÕâЩÎó²îÈÆ¹ýijЩJavaɳÏäÏÞÖÆ¡££¨CVE-2018-2582£¬CVE-2018-2641£©? OpenJDKµÄJNDI×é¼þÖеÄLDAPCertStoreÀàδÄÜÇå¾²µØ´¦Öóͷ£LDAPÒýÓ᣹¥»÷Õß¿ÉÄÜʹÓÃÕâ¸öÎó²î»ñȡ֤ÊéÊý¾Ý¡££¨CVE-2018-2633£©
? ʹÓÃHTTP/SPNEGOÉí·ÝÑé֤ʱ£¬OpenJDKµÄJGSS×é¼þºöÂÔjavax.security.auth.useSubjectCredsOnlyÊôÐÔµÄÖµ£¬²¢Ê¼ÖÕʹÓÃÈ«¾Öƾ֤¡£Õâ»áµ¼ÖÂÈ«¾Öƾ֤±»²»¿ÉÐŵÄJavaÓ¦ÓóÌÐòʹÓᣣ¨CVE-2018-2634£©
? ÔÚijЩÇéÐÎÏ£¬OpenJDKµÄJMX×é¼þÎÞ·¨×¼È·ÉèÖÃSingleEntryRegistryµÄ·´ÐòÁл¯¹ýÂËÆ÷¡£Ô¶³Ì¹¥»÷Õß¿ÉÄÜ»áʹÓÃÕâ¸öÎó²îÈÆ¹ýÔ¤ÆÚµÄ·´ÐòÁл¯ÏÞÖÆ¡££¨CVE-2018-2637£©
? OpenJDKµÄLDAP×é¼þÔÚ°ÑËüÃÇÌí¼Óµ½LDAPËÑË÷ÅÌÎÊʱδÄÜ׼ȷµØ¶ÔÓû§ÃûÖеÄÌØÊâ×Ö·û¾ÙÐбàÂë¡£Ô¶³Ì¹¥»÷Õß¿ÉÄÜʹÓÃÕâ¸öÎó²îÀ´Ê¹ÓÃLdapLoginModuleÀàÖ´ÐеÄLDAPÅÌÎÊ¡££¨CVE-2018-2588£©
? OpenJDKµÄJNDI×é¼þÖеÄDNS¿Í»§¶ËÔÚ·¢ËÍDNSÅÌÎÊʱûÓÐʹÓÃËæ»úÔ´¶Ë¿Ú¡£Õâ¿ÉÄÜ»áʹԶ³Ì¹¥»÷Õ߸üÈÝÒ×ÓÕÆ¶ÔÕâЩÅÌÎʵÄÏìÓ¦¡££¨CVE-2018-2599£©
? OpenJDKµÄI18n×é¼þÔÚ¼ÓÔØ×ÊÔ´°üÀàʱ¿ÉÒÔʹÓò»¿ÉÐŵÄËÑË÷·¾¶¡£ÍâµØ¹¥»÷Õß¿ÉÄÜʹÓÃÕâ¸öÎó²î£¬Í¨¹ýʹJavaÓ¦ÓóÌÐò¼ÓÔØ¹¥»÷Õß¿ØÖƵÄÀàÎļþÀ´Ö´ÐÐÁíÒ»ÍâµØÓû§µÄí§Òâ´úÂë¡££¨CVE-2018-2602£©
? OpenJDKµÄLibraries×é¼þδÄܳä·ÖÏÞÖÆ¶ÁÈ¡DER±àÂëÊäÈëʱ·ÖÅɵÄÄÚ´æÁ¿¡£ÈôÊÇÔ¶³Ì¹¥»÷Õ߯ÊÎöÁ˹¥»÷ÕßÌṩµÄDER±àÂëÊäÈ룬ÔòÔ¶³Ì¹¥»÷Õß¿ÉÄÜ»áʹÓÃÕâ¸öÎó²îʹJavaÓ¦ÓóÌÐòʹÓùý¶àµÄÄÚ´æ¡££¨CVE-2018-2603£©
? OpenJDKµÄJCE×é¼þÖеÄÃÜÔ¿ÐÒéʵÏÖ²¢²»¿É°ü¹Ü×㹻ǿʢµÄÒÑʹÓÃÃÜÔ¿À´³ä·Ö±£»¤ÌìÉúµÄ¹²ÏíÃÜÔ¿¡£Õâ¿ÉÒÔʹ¹¥»÷ÃÜÔ¿ÐÒé¶ø²»ÊÇʹÓÃÐÉÌÉñÃØµÄ¼ÓÃÜÆÆËðÊý¾Ý¼ÓÃܸüÈÝÒס££¨CVE-2018-2618£©
? ÔÚijЩÇéÐÎÏ£¬OpenJDKµÄJGSS×é¼þÔÚÍâµØGSS¿â·â×°Æ÷ÖÐδÄÜ׼ȷ´¦Öóͷ£GSSÉÏÏÂÎÄ¡£Ô¶³Ì¹¥»÷Õß¿ÉÄÜʹÓÃJGSSÀ´Ê¹JavaÓ¦ÓóÌÐòʹÓÃÏÈǰÊͷŵÄÉÏÏÂÎÄ¡££¨CVE-2018-2629£©
? OpenJDKµÄ¿â£¬AWTºÍJNDI×é¼þÖеĶà¸öÀàÔÚ´ÓÐòÁл¯±íµ¥½¨É蹤¾ßʵÀýʱûÓгä·ÖÑéÖ¤ÊäÈë¡£ÌØÖÆµÄÊäÈë¿ÉÄܻᵼÖÂJavaÓ¦ÓóÌÐò½¨Éè¾ßÓÐ·×ÆçÖÂ״̬µÄ¹¤¾ß£¬»òÕßÔÚ·´ÐòÁл¯Ê±Ê¹Óùý¶àµÄÄÚ´æ¡££¨CVE-2018-2663£¬CVE-2018-2677£¬CVE-2018-2678£©
? OpenJDKµÄLibraries×é¼þÖеĶà¸ö¼ÓÃÜÃÜÔ¿ÀàûÓÐ׼ȷµØÍ¬²½¶ÔÆäÄÚ²¿Êý¾ÝµÄ»á¼û¡£Õâ¿ÉÄܻᵼÖ¶àÏß³ÌJavaÓ¦ÓóÌÐò¶ÔÊý¾ÝÓ¦ÓÃÈõ¼ÓÃÜ£¬ÓÉÓÚʹÓÃÁËÒѱ»ÇåÁãµÄÃÜÔ¿¡££¨CVE-2018-2579£©
ÊÜÓ°ÏìµÄ²úÆ·°æ±¾
? Red Hat Enterprise Linux Server 7 x86_64? Red Hat Enterprise Linux Server 6 x86_64
? Red Hat Enterprise Linux Server 6 i386
? Red Hat Enterprise Linux Server - Extended Update Support 7.4 x86_64
? Red Hat Enterprise Linux Server - AUS 7.4 x86_64
? Red Hat Enterprise Linux Workstation 7 x86_64
? Red Hat Enterprise Linux Workstation 6 x86_64
? Red Hat Enterprise Linux Workstation 6 i386
? Red Hat Enterprise Linux Desktop 7 x86_64
? Red Hat Enterprise Linux Desktop 6 x86_64
? Red Hat Enterprise Linux Desktop 6 i386
? Red Hat Enterprise Linux for IBM z Systems 7 s390x
? Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 7.4 s390x
? Red Hat Enterprise Linux for Power big endian 7 ppc64
? Red Hat Enterprise Linux for Power big endian - Extended Update Support 7.4 ppc64
? Red Hat Enterprise Linux for Scientific Computing 7 x86_64
? Red Hat Enterprise Linux for Power little endian 7 ppc64le
? Red Hat Enterprise Linux for Scientific Computing 6 x86_64
? Red Hat Enterprise Linux EUS Compute Node 7.4 x86_64
? Red Hat Enterprise Linux for Power little endian - Extended Update Support 7.4 ppc64le
? Red Hat Enterprise Linux Server - TUS 7.4 x86_64
? Red Hat Enterprise Linux for ARM 64 7 aarch64
? Red Hat Enterprise Linux for Power 9 7 ppc64le
? Red Hat Enterprise Linux Server (for IBM Power LE) - 4 Year Extended Update Support 7.4 ppc64le
? Red Hat Enterprise Linux Server - 4 Year Extended Update Support 7.4 x86_64
ÐÞ¸´ÇéÐÎ
? BJ - 1534263 - CVE-2018-2678 OpenJDK£ºBasicAttributes·´ÐòÁл¯ÖеÄÎÞÏÞÄÚ´æ·ÖÅÉ£¨JNDI£¬8191142£©
? BZ - 1534288 - CVE-2018-2677 OpenJDK£º
·´ÐòÁл¯Ê±´úµÄÎÞÏÞÄÚ´æ·ÖÅÉ£¨AWT£¬8190289£©
? BZ - 1534296 - CVE-2018-2663 OpenJDK£º
ArrayBlockingQueue·´ÐòÁл¯Îª·×ÆçÖÂ״̬£¨¿â£¬8189284£©
? BZ - 1534298 - CVE-2018-2579 OpenJDK£º
¶Ô¼ÓÃÜÃÜÔ¿Êý¾ÝµÄ·Çͬ²½»á¼û£¨¿â£¬8172525£©
? BZ - 1534299 - CVE-2018-2588 OpenJDK£º
LdapLoginModule LDAPÅÌÎÊÖÐÓû§Ãû±àÂëȱ·¦£¨LDAP£¬8178449£©
? BZ - 1534525 - CVE-2018-2602 OpenJDK£º
´Ó²»ÊÜÐÅÍеÄλÖüÓÔØÀࣨI18n£¬8182601£©
? BZ - 1534543 - CVE-2018-2599 OpenJDK£º
DnsClientȱÉÙÔ´¶Ë¿ÚËæ»ú»¯£¨JNDI£¬8182125£©
? BZ - 1534553 - CVE-2018-2603 OpenJDK£º
DerValueÎÞÏÞÄÚ´æ·ÖÅÉ£¨¿â£¬8182387£©
? BJ - 1534625 - CVE-2018-2629 OpenJDK£º
GSSÉÏÏÂÎÄʹÓúóÃâ·Ñ£¨JGSS£¬8186212£©
? BZ - 1534762 - CVE-2018-2618 OpenJDK£º
ÃÜÔ¿ÐÒéȱ·¦£¨JCE£¬8185292£©
? BJ - 1534766 - CVE-2018-2641 OpenJDK£º
GTK¿â¼ÓÔØºóʹÓã¨AWT£¬8185325£©
? BZ - 1534768 - CVE-2018-2582 OpenJDK£º
invokeinterfaceÖ¸ÁîµÄÑé֤ȱ·¦£¨Hotspot£¬8174962£©
? BZ - 1534943 - CVE-2018-2634 OpenJDK£º
ʹÓÃHTTP / SPNEGOµÄÈ«¾Öƾ֤£¨JGSS£¬8186600£©
? BZ - 1534970 - CVE-2018-2637 OpenJDK£º
SingleEntryRegistry·´ÐòÁл¯¹ýÂËÆ÷µÄ¹ýʧÉèÖã¨JMX£¬8186998£©
? BZ - 1535036 - CVE-2018-2633 OpenJDK£º
LDAPCertStore²»Çå¾²´¦Öóͷ£LDAPÒýÓã¨JNDI£¬8186606£©
½â¾ö¼Æ»®
Óû§Ó¦¸ÃʵʱÉý¼¶¾ÙÐзÀ»¤£¬¹ØÓÚÔõÑùÓ¦Óô˴θüÐÂÀ´ÐÞ¸´ÉÏÊöÎó²î£¬Çë²Î¿¼£º
https://access.redhat.com/articles/11258
Éù Ã÷
±¾Ç徲ͨ¸æ½öÓÃÀ´ÐÎò¿ÉÄܱ£´æµÄÇå¾²ÎÊÌ⣬AG¹«Ë¾¿Æ¼¼²»Îª´ËÇ徲ͨ¸æÌṩÈκΰü¹Ü»òÔÊÐí¡£ÓÉÓÚÈö²¥¡¢Ê¹ÓôËÇ徲ͨ¸æËùÌṩµÄÐÅÏ¢¶øÔì³ÉµÄÈκÎÖ±½Ó»òÕß¼ä½ÓµÄЧ¹û¼°Ëðʧ£¬¾ùÓÉʹÓÃÕß×Ô¼ºÈÏÕæ£¬AG¹«Ë¾¿Æ¼¼ÒÔ¼°Ç徲ͨ¸æ×÷Õß²»Îª´Ë¼ç¸ºÈκÎÔðÈΡ£AG¹«Ë¾¿Æ¼¼ÓµÓжԴËÇ徲ͨ¸æµÄÐÞ¸ÄÏ¢ÕùÊÍȨ¡£ÈçÓû×ªÔØ»òÈö²¥´ËÇ徲ͨ¸æ£¬±ØÐè°ü¹Ü´ËÇ徲ͨ¸æµÄÍêÕûÐÔ£¬°üÀ¨°æÈ¨ÉùÃ÷µÈËùÓÐÄÚÈÝ¡£Î´¾AG¹«Ë¾¿Æ¼¼ÔÊÐí£¬²»µÃí§ÒâÐ޸ĻòÕßÔö¼õ´ËÇ徲ͨ¸æÄÚÈÝ£¬²»µÃÒÔÈκη½·¨½«ÆäÓÃÓÚÉÌҵĿµÄ¡£
AG¹«Ë¾ÔÆ





