Update of Java SE, MySQL, VirtualBox and other Oracle products addressing vulnerabilities.

Oracle Corporation released scheduled release of updates for its products (Critical Patch Update) aimed at addressing critical issues and vulnerabilities. The April update resolved a total of 297 vulnerabilities.

In releases Java SE 12.0.1, 11.0.3, and 8u212 five security issues were resolved. All vulnerabilities can be exploited remotely without authentication. One vulnerability specific to the Windows platform, has been assigned CVSS Score 9.0 (CVE-2019-2699), corresponds to a critical level of severity and allows an unauthenticated user to compromise Java SE applications over the network. Two vulnerabilities in the 2D graphics processing subsystem were assigned a rating of 8.1 (CVE-2019-2697, CVE-2019-2698). Details are not yet disclosed.

In addition to the issues in Java SE, vulnerabilities have also been disclosed in other Oracle products, including:

  • 40 vulnerabilities in MySQL (maximum severity level 7.5). The most serious issue
    (CVE-2019-2632) affects the authentication plugin subsystem. Issues will be resolved in the releases MySQL Community Server 8.0.16, 5.7.26, and 5.6.44.
  • 12 vulnerabilities in VirtualBox, seven of which have a critical degree of severity (CVSS Score 8.8). Vulnerabilities have been resolved in the updates VirtualBox 6.0.6 and 5.2.28 (in note (the fact of resolving security issues is not publicized). Details are not disclosed, but judging by the CVSS level, vulnerabilities have been resolved that demonstrated at the Pwn2Own 2019 competition and allow code execution on the host system from the guest system environment.

    allow an attack on the host system from the guest environment.

  • 3 vulnerabilities In Solaris (maximum severity level 5.3 — issues in the IPS package manager, SunSSH, and the lock management service. Problems have been resolved in the release
    Solaris 11.4 SRU8, which also reinstates support for UCB libraries (libucb, librpcsoc, libdbm, libtermcap, libcurses) and the fc-fabric service, updates the versions of packages
    ibus 1.5.19, NTP 4.2.8p12,
    Firefox 60.6.0esr,
    BIND 9.11.6,
    OpenSSL 1.0.2r,
    MySQL 5.6.43 & 5.7.25,
    libxml2 2.9.9,
    libxslt 1.1.33,
    Wireshark 2.6.7,
    ncurses 6.1.0.20190105,
    Apache httpd 2.4.38,
    perl 5.22.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster