Updates for Java SE, MySQL, VirtualBox and other Oracle products with vulnerabilities fixed

Oracle Company ΠΎΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π»Π° scheduled release of updates to their products (Critical Patch Update), aimed at eliminating critical problems and vulnerabilities. In the January update, the amount eliminated 334 vulnerabilities.

In issues Java SE 13.0.2, 11.0.6 and 8u241 eliminated 12 security issues. All vulnerabilities can be exploited remotely without authentication. The highest severity level is 8.1, which is assigned to a serialization issue (CVE-2020-2604) that allows Java SE applications to be compromised by passing specially crafted serialized data. Three vulnerabilities have a severity level of 7.5. These issues are present in JavaFX and are caused by vulnerabilities in SQLite and libxslt.

In addition to issues in Java SE, vulnerabilities have been made public in other Oracle products, including:

  • 12 vulnerabilities in MySQL server and
    3 vulnerabilities in MySQL client implementation (C API). The highest severity level of 6.5 is assigned to three problems in the MySQL parser and optimizer.
    Issues fixed in releases MySQL Community Server 8.0.19, 5.7.29 and 5.6.47.

  • 18 vulnerabilities in VirtualBox, of which 6 have a high degree of danger (CVSS Score 8.2 and 7.5). Vulnerabilities will be fixed in updates VirtualBox 6.1.2, 6.0.16 and 5.2.36that are expected today.
  • 10 vulnerabilities in Solaris. Maximum Severity 8.8 is a locally exploited issue in the Common Desktop Environment. Of the problems with a severity level above 7, local vulnerabilities in Consolidation Infrastructure and the file system can also be noted. Issues fixed in yesterday's update Solaris 11.4 SRU 17.

Source: opennet.ru

Add a comment