🍏 iOS / Mac OSDisney Plus: Jetzt streikt auch AirPlay(15.09.2026 um 20:09 Uhr)
🍏 iOS / Mac OSAnalyst: iPhone 18 Pro Vorbestellungen verhalten gestartet(15.09.2026 um 20:12 Uhr)
🍏 iOS / Mac OSAmazon Music Unlimited: bis zu 4 Gratis-Monate erhalten(15.09.2026 um 21:30 Uhr)
🔧 ProgrammierungGitHub Copilot suggests custom properties definitions(15.09.2026 um 21:07 Uhr)
🍏 iOS / Mac OSDisney Plus: Jetzt streikt auch AirPlay(15.09.2026 um 20:09 Uhr)
🍏 iOS / Mac OSAnalyst: iPhone 18 Pro Vorbestellungen verhalten gestartet(15.09.2026 um 20:12 Uhr)
🍏 iOS / Mac OSAmazon Music Unlimited: bis zu 4 Gratis-Monate erhalten(15.09.2026 um 21:30 Uhr)
🔧 ProgrammierungGitHub Copilot suggests custom properties definitions(15.09.2026 um 21:07 Uhr)
1 Tag Serie
🐧 Unix Server 🕛 vor 6 Jahren 4 Min Lesezeit CVE-2020-2754
0

USN-4337-1: OpenJDK vulnerabilities

Cyber Threat & Vulnerability Dossier CVSS 5.8 MEDIUM (Heuristik) EPSS 3.8%
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
⛔ Dienstausfall (DoS) / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
Im CVE-Radar öffnen
↗ Quelle (usn.ubuntu.com)
🗣️ Stimme:
📑 Inhaltsübersicht

openjdk-8, openjdk-lts vulnerabilities



A security issue affects these releases of Ubuntu and its derivatives:



  • Ubuntu 19.10

  • Ubuntu 18.04 LTS

  • Ubuntu 16.04 LTS

Summary



Several security issues were fixed in OpenJDK.



Software Description



  • openjdk-8 - Open Source Java implementation

  • openjdk-lts - Open Source Java implementation

Details



It was discovered that OpenJDK incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause a denial of
service while processing a specially crafted regular expression.
(CVE-2020-2754, CVE-2020-2755)



It was discovered that OpenJDK incorrectly handled class descriptors and
catching exceptions during object stream deserialization. An attacker could
possibly use this issue to cause a denial of service while processing a
specially crafted serialized input. (CVE-2020-2756, CVE-2020-2757)



Bengt Jonsson, Juraj Somorovsky, Kostis Sagonas, Paul Fiterau Brostean and
Robert Merget discovered that OpenJDK incorrectly handled certificate messages
during TLS handshake. An attacker could possibly use this issue to bypass
certificate verification and insert, edit or obtain sensitive information. This
issue only affected OpenJDK 11. (CVE-2020-2767)



It was discovered that OpenJDK incorrectly handled exceptions thrown by
unmarshalKeyInfo() and unmarshalXMLSignature(). An attacker could possibly use
this issue to cause a denial of service while reading key info or XML signature
data from XML input. (CVE-2020-2773)



Peter Dettman discovered that OpenJDK incorrectly handled SSLParameters in
setAlgorithmConstraints(). An attacker could possibly use this issue to
override the defined systems security policy and lead to the use of weak
crypto algorithms that should be disabled. This issue only affected
OpenJDK 11. (CVE-2020-2778)



Simone Bordet discovered that OpenJDK incorrectly re-used single null TLS
sessions for new TLS connections. A remote attacker could possibly use this
issue to cause a denial of service. (CVE-2020-2781)



Dan Amodio discovered that OpenJDK did not restrict the use of CR and LF
characters in values for HTTP headers. An attacker could possibly use this
issue to insert, edit or obtain sensitive information. (CVE-2020-2800)



Nils Emmerich discovered that OpenJDK incorrectly checked boundaries or
argument types. An attacker could possibly use this issue to bypass sandbox
restrictions causing unspecified impact. (CVE-2020-2803, CVE-2020-2805)



It was discovered that OpenJDK incorrectly handled application data packets
during TLS handshake. An attacker could possibly use this issue to insert,
edit or obtain sensitive information. This issue only affected OpenJDK 11.
(CVE-2020-2816)



It was discovered that OpenJDK incorrectly handled certain regular
expressions. An attacker could possibly use this issue to cause a denial of
service. (CVE-2020-2830)



Update instructions



The problem can be corrected by updating your system to the following package versions:



Ubuntu 19.10









Ubuntu 18.04 LTS









Ubuntu 16.04 LTS






To update your system, please follow these instructions:







  • Vollständiger Original-Bericht
    Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf usn.ubuntu.com.
    ↗ Original-Artikel auf usn.ubuntu.com lesen
    Wie bewertest du diesen Beitrag?
    1 Klick Feedback
    Teilen mit Netzwerk & Team:

    Community-Analysen & Experten-Meinungen 0

    Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
    Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
    Community Pulse: Relevanz-Einschätzung
    1 Klick Experten-Votum
    🔴 Akute Relevanz 0%
    🟡 In Evaluierung 0%
    🟢 Keine Auswirkung 0%
    Spannende Innovation 0%
    Verwandte Story-Cluster & Quellen (Vektor-KI)
    Port 8095 Engine
    1 Quelle
    Set up sharing boundaries for Google Drive with unified data protection rules
    1 Quelle
    Gmail Search’s AI Overviews now available globally
    1 Quelle
    CVE-2026-58695 | Google Android phy_power.c gmc_phy_lp3_exit_restore_registers memory corruption
    Ähnliche Beiträge
    🔍 Verwandte News

    Auch interessante Nachrichten USN-4337-1: OpenJDK vulnerabilities

    Thematisch verwandte Begriffe: USN43371, OpenJDK, vulnerabilities · 6 Treffer

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...

    Laden...

    Beiträge werden geladen ...

    Laden...

    Videos werden geladen ...