QID 378132

Date Published: 2023-04-04

QID 378132: Red Hat OpenJDK 8u312 Windows Builds release and Security Update (RHSA-2021:3961)

The OpenJDK 8 packages provide the OpenJDK 8 Java Runtime Environment and the OpenJDK 8 Java Software Development Kit.

Loop in HttpsServer triggered during TLS session close (JSSE, 8254967) (CVE-2021-35565)

Incorrect principal selection when using Kerberos Constrained Delegation (Libraries, 8266689) (CVE-2021-35567)

Weak ciphers preferred over stronger ones for TLS (JSSE, 8264210) (CVE-2021-35550)

Excessive memory allocation in RTFParser (Swing, 8265167) (CVE-2021-35556)

Excessive memory allocation in RTFReader (Swing, 8265580) (CVE-2021-35559)

Excessive memory allocation in HashMap and HashSet (Utility, 8266097) (CVE-2021-35561)

Certificates with end dates too far in the future can corrupt keystore (Keytool, 8266137) (CVE-2021-35564)

Unexpected exception raised during TLS handshake (JSSE, 8267729) (CVE-2021-35578)

Excessive memory allocation in BMPImageReader (ImageIO, 8267735) (CVE-2021-35586)

Incomplete validation of inner class references in ClassFileParser (Hotspot, 8268071) (CVE-2021-35588)

Non-constant comparison during TLS handshakes (JSSE, 8269618) (CVE-2021-35603)
Affected Versions:
Red Hat build of OpenJDK 8 (1.8.0.302) and later Versions and Prior to OpenJDK 8 (1.8.0.312)

QID Detection Logic (Authenticated)
This QID checks for the below registry keys HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall" ,"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall and sub values to check Publisher and Display version.

Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java

  • CVSS V3 rated as High - 6.8 severity.
  • CVSS V2 rated as High - 7.1 severity.
  • Solution
    For more information regarding the update RHSA-2021:3961
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    RHSA-2021:3961 URL Logo access.redhat.com/errata/RHSA-2021:3961