RHSA-2019:0640: Moderate: java-1.8.0-ibm security update
IBM Java SE version 8 includes the IBM Java Runtime Environment and the IBM Java Software Development Kit.This update upgrades IBM Java SE 8 to version 8 SR5-FP30.Security Fix(es): IBM JDK: buffer overflow in jiosnprintf() and jiovsnprintf() (CVE-2018-12547) IBM JDK: missing null check when accelerating Unsafe calls (CVE-2018-12549) OpenJDK: memory disclosure in FileChannelImpl (Libraries, 8206290) (CVE-2019-2422) libjpeg-turbo: Divide By Zero in allocsarray function in jmemmgr.c (CVE-2018-11212) Oracle JDK: unspecified vulnerability fixed in 8u201 (Deployment) (CVE-2019-2449) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:0640?
The severity of RHSA-2019:0640 is classified as moderate due to the identified buffer overflow vulnerabilities.
How do I fix RHSA-2019:0640?
To fix RHSA-2019:0640, you should upgrade IBM Java SE to version 8 SR5-FP30.
What vulnerabilities are addressed by RHSA-2019:0640?
RHSA-2019:0640 addresses a buffer overflow vulnerability in jio_snprintf() and jio_vsnprintf() identified as CVE-2018-12547.
Which software packages are affected by RHSA-2019:0640?
The affected packages by RHSA-2019:0640 include java-1.8.0-ibm and java-1.8.0-ibm-devel up to version 1.8.0-ibm-1.8.0.5.30-1jpp.1.el6_10.
Is RHSA-2019:0640 applicable to all IBM Java SE installations?
RHSA-2019:0640 is specifically applicable to installations of IBM Java SE version 8 in affected Red Hat environments.