REDHAT-BUG-2015061: Medium severity OpenJDK Keytool vulnerability
Published Oct 18, 2021
·Updated
A flaw was found in the way the Keytool component of OpenJDK handled X.509 certificates with validity period ending too far in the future, after year 9999. When such certificates were imported into a keystore, they could cause corruption of the keystore.
Affected Software
1 affected component
OpenJDK Keytool
Event History
Oct 18, 2021
Data Sourced
via Red Hat·10:24 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2015061?
The severity of REDHAT-BUG-2015061 is classified as moderate.
2
How do I fix REDHAT-BUG-2015061?
To fix REDHAT-BUG-2015061, update OpenJDK Keytool to the latest version provided by your distribution.
3
What are the consequences of ignoring REDHAT-BUG-2015061?
Ignoring REDHAT-BUG-2015061 could lead to keystore corruption when invalid certificates are imported.
4
Which versions of OpenJDK Keytool are affected by REDHAT-BUG-2015061?
All versions of OpenJDK Keytool prior to the patch that addresses REDHAT-BUG-2015061 are affected.
5
Is there a workaround for REDHAT-BUG-2015061?
There is no official workaround for REDHAT-BUG-2015061 other than avoiding the import of problematic certificates.