Oracle has released a planned update for its products (Critical Patch Update) aimed at addressing critical issues and vulnerabilities. The October update fixes a total of 387 vulnerabilities.
Some issues:
- 3 security issues in Java SE and 4 issues in GraalVM for JDK. All vulnerabilities can be exploited remotely without authentication and affect environments that allow the execution of untrusted code. The issues have a moderate severity level — the most dangerous vulnerabilities in Java SE have a severity of 5.3 (in CORBA and JSSE), while in GraalVM it is 7.5 (Node.js). The vulnerabilities were fixed in releases Java SE 21.0.1 and 17.0.9.
- There are 26 vulnerabilities in server MySQL has two vulnerabilities that can be exploited remotely. The most serious issues, related to the use of the Curl package, OpenSSL library, and optimizer, are assigned severity levels of 7.5 and 6.5. Less critical vulnerabilities affect the optimizer, InnoDB, DDL, UDF, and encryption tools. The issues will be fixed in MySQL Community Server releases 8.1.1, 8.0.35, and 5.7.44.
- 3 vulnerabilities in VirtualBox with severity levels of 7.9 and 7.3. The vulnerabilities are fixed in VirtualBox 7.0.12 update (branch 6.1 is not affected by these vulnerabilities).
- 2 vulnerabilities in Solaris affecting the kernel and file system. The issues are assigned severity levels of 5.5 and 3.1. The vulnerabilities are fixed in Solaris 11.4 SRU62 update. In addition to fixing vulnerabilities, the new version also updates the versions of packages python 3.7.17, rabbitmq 3.8.35, Firefox 102.15.0esr, Thunderbird 102.15.0, pcre2 10.42, unrar 6.2.10, PHP 8.2.10, Tomcat 8.5.93, mod_jk 1.2.49, cups, perl, ucups, and zfs.
Source: opennet.ru
