Scientific Linux Security Update : java-11-openjdk on SL7.x x86_64 (20201022)

medium Nessus Plugin ID 141842


VPR Score: 3.3


The remote Scientific Linux host is missing one or more security updates.


Security Fix(es) :

- OpenJDK: Credentials sent over unencrypted LDAP connection (JNDI, 8237990) (CVE-2020-14781)

- OpenJDK: Certificate blacklist bypass via alternate certificate encodings (Libraries, 8237995) (CVE-2020-14782)

- OpenJDK: Integer overflow leading to out-of-bounds access (Hotspot, 8241114) (CVE-2020-14792)

- OpenJDK: Incomplete check for invalid characters in URI to path conversion (Libraries, 8242685) (CVE-2020-14797)

- OpenJDK: Race condition in NIO Buffer boundary checks (Libraries, 8244136) (CVE-2020-14803)

- OpenJDK: High memory usage during deserialization of Proxy class with many interfaces (Serialization, 8236862) (CVE-2020-14779)

- OpenJDK: Missing permission check in path to URI conversion (Libraries, 8242680) (CVE-2020-14796)


Update the affected packages.

