Updates for Java SE, MySQL, VirtualBox and other Oracle products with vulnerabilities fixed

Oracle Company ΠΎΠΏΡƒΠ±Π»ΠΈΠΊΠΎΠ²Π°Π»Π° scheduled release of updates to their products (Critical Patch Update), aimed at eliminating critical problems and vulnerabilities. In the January update, the amount eliminated 397 vulnerabilities.

In issues Java SE 14.0.1, 11.0.7 and 8u251 eliminated 15 security issues. All vulnerabilities can be exploited remotely without authentication. The highest severity level is 8.3, which is assigned to problems in libraries (CVE-2020-2803, CVE-2020-2805). Two vulnerabilities (in libxslt and JSSE) are rated 8.1 and 7.5.

In addition to issues in Java SE, vulnerabilities have been made public in other Oracle products, including:

  • 35 vulnerabilities in MySQL server and
    2 vulnerabilities in MySQL client implementation (C API). The highest severity level of 9.8 is assigned to the CVE-2019-5482 vulnerability, which manifests itself when compiling with cURL support. Issues fixed in releases MySQL Community Server 8.0.20, 5.7.30 and 5.6.49.

  • 19 vulnerabilities, of which 7 problems have a critical severity level (CVSS is greater than 8). Including fixed vulnerabilities used in attacks demonstrated at the competition Pwn2Own 2020 and allowing through manipulations on the side of the guest system to gain access to the host system and execute code with hypervisor rights. Vulnerabilities fixed in updates VirtualBox 6.1.6, 6.0.20 and 5.2.40.
  • 6 vulnerabilities in Solaris. Maximum Hazard Degree 8.8 - Locally Operated problem in the Common Desktop Environment, allowing an unprivileged user to have code run as root. Issues have also been fixed in the SMB kernel module, in Whodo, and in the SMF svcbundle command. Issues fixed in yesterday's update Solaris 11.4 SRU 20.

Source: opennet.ru

Add a comment