QID 352872
Date Published: 2021-11-15
QID 352872: Amazon Linux Security Advisory for java-11-amazon-corretto : ALAS2-2021-1718
there is a flaw in the xml entity encoding functionality of libxml2.
An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of libxml2 could trigger an out-of-bounds read.
The most likely impact of this flaw is to application availability, with some potential impact to confidentiality and integrity if an attacker is able to use memory information to further exploit the application. (
( CVE-2021-3517) a flaw was found in gstreamer-plugins-base where an out-of-bounds read when handling certain id3v2 tags is possible.
The highest threat from this vulnerability is to system availability. (
( CVE-2021-3522) vulnerability in the java se, oracle graalvm enterprise edition product of oracle java se (component: jsse).
Supported versions that are affected are java se: 7u311, 8u301, 11.0.12; oracle graalvm enterprise edition: 20.3.3 and 21.2.0.
Difficult to exploit vulnerability allows unauthenticated attacker with network access via tls to compromise java se, oracle graalvm enterprise edition.
Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all java se, oracle graalvm enterprise edition accessible data.
Note: this vulnerability applies to java deployments, typically in clients running sandboxed java web start applications or sandboxed java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the java sandbox for security.
This vulnerability can also be exploited by using apis in the specified component, e.g., through a web service which supplies data to the apis.
Cvss 3.1 base score 5.9 (confidentiality impacts).
Allows unauthorized disclosure of information; allows unauthorized modification; allows disruption of service.
- ALAS2-2021-1718 -
alas.aws.amazon.com/AL2/ALAS-2021-1718.html
CVEs related to QID 352872
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2-2021-1718 | Amazon Linux 2 |
|