Oracle Corporation scheduled release of updates for its products (Critical Patch Update) aimed at addressing critical issues and vulnerabilities. The April update resolved a total of .
In releases five security issues were resolved. All vulnerabilities can be exploited remotely without authentication. One vulnerability specific to the Windows platform, CVSS Score 9.0 (CVE-2019-2699), corresponds to a critical level of severity and allows an unauthenticated user to compromise Java SE applications over the network. Two vulnerabilities in the 2D graphics processing subsystem were assigned a rating of 8.1 (CVE-2019-2697, CVE-2019-2698). Details are not yet disclosed.
In addition to the issues in Java SE, vulnerabilities have also been disclosed in other Oracle products, including:
- in MySQL (maximum severity level 7.5). The most serious issue
() affects the authentication plugin subsystem. Issues will be resolved in the releases . - in VirtualBox, seven of which have a critical degree of severity (CVSS Score 8.8). Vulnerabilities have been resolved in the updates (in (the fact of resolving security issues is not publicized). Details are not disclosed, but judging by the CVSS level, vulnerabilities have been resolved that at the Pwn2Own 2019 competition and allow code execution on the host system from the guest system environment.
allow an attack on the host system from the guest environment.
- In Solaris (maximum severity level 5.3 — issues in the IPS package manager, SunSSH, and the lock management service. Problems have been resolved in the release
, which also reinstates support for UCB libraries (libucb, librpcsoc, libdbm, libtermcap, libcurses) and the fc-fabric service, updates the versions of packages
ibus 1.5.19, NTP 4.2.8p12,
Firefox 60.6.0esr,
BIND 9.11.6,
OpenSSL 1.0.2r,
MySQL 5.6.43 & 5.7.25,
libxml2 2.9.9,
libxslt 1.1.33,
Wireshark 2.6.7,
ncurses 6.1.0.20190105,
Apache httpd 2.4.38,
perl 5.22.
Source: opennet.ru
