Amazon Linux 2 : java-11-amazon-corretto (ALAS-2019-1246)

medium Nessus Plugin ID 126958

Synopsis

The remote Amazon Linux 2 host is missing a security update.

Description

OpenJDK: Insufficient restriction of privileges in AccessController (Security, 8216381) (CVE-2019-2786)

OpenJDK: Unbounded memory allocation during deserialization in Collections (Utilities, 8213432) (CVE-2019-2769)

libpng: png_image_free in png.c in libpng has a use-after-free because png_image_free_function is called under png_safe_execute.
(CVE-2019-7317)

OpenJDK: Insufficient checks of suppressed exceptions in deserialization (Utilities, 8212328) (CVE-2019-2762)

OpenJDK: Insufficient permission checks for file:// URLs on Windows (Networking, 8213431) (CVE-2019-2766)

OpenJDK: Non-constant time comparison in ChaCha20Cipher (Security, 8221344) (

CVE-2019-2818)

OpenJDK: Missing URL format validation (Networking, 8221518) (CVE-2019-2816)

OpenJDK: Side-channel attack risks in Elliptic Curve (EC) cryptography (Security, 8208698) (CVE-2019-2745)

OpenJDK: Incorrect handling of certificate status messages during TLS handshake (JSSE, 8222678) (CVE-2019-2821)

Solution

Run 'yum update java-11-amazon-corretto' to update your system.

See Also

https://alas.aws.amazon.com/AL2/ALAS-2019-1246.html

Plugin Details

Severity: Medium

ID: 126958

File Name: al2_ALAS-2019-1246.nasl

Version: 1.7

Type: local

Agent: unix

Published: 7/24/2019

Updated: 12/7/2022

Supported Sensors: Frictionless Assessment Agent, Frictionless Assessment AWS, Nessus Agent, Agentless Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2019-2816

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:amazon:linux:java-11-amazon-corretto, p-cpe:/a:amazon:linux:java-11-amazon-corretto-headless, p-cpe:/a:amazon:linux:java-11-amazon-corretto-javadoc, cpe:/o:amazon:linux:2

Required KB Items: Host/local_checks_enabled, Host/AmazonLinux/release, Host/AmazonLinux/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 7/18/2019

Vulnerability Publication Date: 2/4/2019

Reference Information

CVE: CVE-2019-2745, CVE-2019-2762, CVE-2019-2766, CVE-2019-2769, CVE-2019-2786, CVE-2019-2816, CVE-2019-2818, CVE-2019-2821, CVE-2019-7317

ALAS: 2019-1246