Debian 9942 Published by

An openjdk-11 security update has been released for Debian GNU/Linux 10 to address several vulnerabilities.



DSA 4734-1: openjdk-11 security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-4734-1 security@debian.org
  https://www.debian.org/security/ Moritz Muehlenhoff
July 26, 2020   https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : openjdk-11
CVE ID : CVE-2020-14556 CVE-2020-14562 CVE-2020-14573 CVE-2020-14577
CVE-2020-14578 CVE-2020-14579 CVE-2020-14581 CVE-2020-14583
CVE-2020-14593 CVE-2020-14621

Several vulnerabilities have been discovered in the OpenJDK Java runtime,
resulting in denial of service, bypass of access/sandbox restrictions or
information disclosure.

For the stable distribution (buster), these problems have been fixed in
version 11.0.8+10-1~deb10u1.

We recommend that you upgrade your openjdk-11 packages.

For the detailed security status of openjdk-11 please refer to
its security tracker page at:
  https://security-tracker.debian.org/tracker/openjdk-11

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at:   https://www.debian.org/security/