Re: [SECURITY] [DLA 2634-1] openjdk-8 security update
+deb8u1 ? Shouldn't it be +deb9u1 ?
Le 23 avril 2021 13:31:18 GMT+02:00, Emilio Pozuelo Monfort <pochu@debian.org> a écrit :
>-------------------------------------------------------------------------
>Debian LTS Advisory DLA-2634-1 debian-lts@lists.debian.org
>https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
>April 23, 2021 https://wiki.debian.org/LTS
>-------------------------------------------------------------------------
>
>Package : openjdk-8
>Version : 8u292-b10-0+deb8u1
>CVE ID : CVE-2021-2161 CVE-2021-2163
>
>Several vulnerabilities have been discovered in the OpenJDK Java runtime,
>resulting in bypass of sandbox restrictions.
>
>For Debian 9 stretch, these problems have been fixed in version
>8u292-b10-0+deb8u1.
>
>We recommend that you upgrade your openjdk-8 packages.
>
>For the detailed security status of openjdk-8 please refer to
>its security tracker page at:
>https://security-tracker.debian.org/tracker/openjdk-8
>
>Further information about Debian LTS security advisories, how to apply
>these updates to your system and frequently asked questions can be
>found at: https://wiki.debian.org/LTS
--
Envoyé de mon appareil Android avec Courriel K-9 Mail. Veuillez excuser ma brièveté.
Reply to: