QID 198752
Date Published: 2022-04-28
QID 198752: Ubuntu Security Notification for Open Java Development Toolkit (OpenJDK) Vulnerabilities (USN-5388-2)
Openjdk incorrectly verified ecdsa signatures.
Openjdk incorrectly limited memory when compiling aspecially crafted xpath expression.
Openjdk incorrectly handled converting certainobject arguments into their textual representations.
Openjdk incorrectly validated the encoded length ofcertain object identifiers.
Openjdk incorrectly validated certain paths.
Openjdk incorrectly parsed certain uri strings.
Anattacker could use this issue to bypass the signature verification process.
An attacker could possibly use thisissue to cause a denial of service.
An attacker couldpossibly use this issue to cause a denial of service.
An attacker could possibly use this issue tocause a denial of service.
Anattacker could possibly use this issue to bypass the secure validationfeature and expose sensitive information in xml files.
Anattacker could possibly use this issue to make applications acceptinvalid of malformed uri strings.
- USN-5388-2 -
ubuntu.com/security/notices/USN-5388-2
CVEs related to QID 198752
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-5388-2 | Ubuntu Linux |
|