Debian Security Advisory

DLA-1339-1 openjdk-7 -- LTS security update

Date Reported:
03 Apr 2018
Affected Packages:
openjdk-7
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 891330.
In Mitre's CVE dictionary: CVE-2018-2579, CVE-2018-2588, CVE-2018-2599, CVE-2018-2602, CVE-2018-2603, CVE-2018-2618, CVE-2018-2629, CVE-2018-2633, CVE-2018-2634, CVE-2018-2637, CVE-2018-2641, CVE-2018-2663, CVE-2018-2677, CVE-2018-2678.
More information:

Several vulnerabilities have been discovered in OpenJDK, an implementation of the Oracle Java platform, resulting in denial of service, unauthorized access, sandbox bypass or HTTP header injection.

For Debian 7 Wheezy, these problems have been fixed in version 7u171-2.6.13-1~deb7u1.

We recommend that you upgrade your openjdk-7 packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS