First published: Tue Jun 27 2023(Updated: )
Migration Toolkit for Runtimes 1.1.1 ZIP artifacts<br>Security Fix(es):<br><li> htmlUnit: Stack overflow crash causes Denial of Service (DoS) (CVE-2023-2798)</li> <li> zip4j: does not always check the MAC when decrypting a ZIP archive (CVE-2023-22899)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software | Affected Version | How to fix |
---|---|---|
htmlUnit | ||
zip4j | ||
Oracle Migration Toolkit for Runtimes |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
RHSA-2023:3814 addresses a stack overflow crash causing Denial of Service (CVE-2023-2798) and incomplete MAC checks when decrypting ZIP archives (CVE-2023-22899).
The severity of RHSA-2023:3814 is classified as moderate due to the potential impact of the vulnerabilities on affected systems.
To fix RHSA-2023:3814, you should update the affected components to their patched versions as recommended by the advisory.
RHSA-2023:3814 affects the Migration Toolkit for Runtimes, htmlUnit, and zip4j.
Yes, there is a risk of Denial of Service due to the stack overflow flaw in htmlUnit addressed by RHSA-2023:3814.