Errata overview
Errata ID 427
Date 2018-08-08
Source package openjdk-7
Fixed in version 7u181-2.6.14-1~deb8u1A~4.2.4.201808071712
Description
This update addresses the following issues:
* Improve key keying case (CVE-2018-2579)
* Improve LDAP logins (CVE-2018-2588)
* Improve reliability of DNS lookups (CVE-2018-2599)
* Improve usage messages (CVE-2018-2602)
* Improve PKCS usage (CVE-2018-2603)
* Stricter key generation (CVE-2018-2618)
* Improve GSS handling (CVE-2018-2629)
* Improve LDAP lookup robustness (CVE-2018-2633)
* Improve property negotiations (CVE-2018-2634)
* Improve JMX supportive features (CVE-2018-2637)
* Improve GTK initialization (CVE-2018-2641)
* More refactoring for deserialization cases (CVE-2018-2663)
* More refactoring for client deserialization cases (CVE-2018-2677)
* More refactoring for naming deserialization cases (CVE-2018-2678)
* incorrect merging of sections in the JAR manifest (CVE-2018-2790)
* unrestricted deserialization of data from JCEKS key stores (CVE-2018-2794)
* insufficient consistency checks in deserialization of multiple classes
  (CVE-2018-2795)
* unbounded memory allocation during deserialization in PriorityBlockingQueue
  (CVE-2018-2796)
* unbounded memory allocation during deserialization in TabularDataSupport
  (CVE-2018-2797)
* unbounded memory allocation during deserialization in Container
  (CVE-2018-2798)
* unbounded memory allocation during deserialization in NamedNodeMapImpl
  (CVE-2018-2799)
* RMI HTTP transport enabled by default (CVE-2018-2800)
* incorrect handling of Reference clones can lead to sandbox bypass
  (CVE-2018-2814)
* unbounded memory allocation during deserialization in StubIORImpl
  (CVE-2018-2815)
* CORBA communication improvements (S8160104)
* Extra validation for public keys (S8174756)
* Improve host instance supports (S8175932)
* Revise default document styling (S8176458)
* Better use of certificates in LDAP (S8178458)
* Better RSA parameters (S8178466)
* Cleaner print job handling (S8179536)
* Cleaner palette entry handling (S8179990)
* Cleaner native graphics device handling (S8180011)
* Cleaner AWT robot handling (S8180015)
* Improve SymbolHashMap entry handling (S8180020)
* Cleaner CLR invocation handling (S8180433)
* More deeply colored ICC spaces (S8180877)
* Improve JVM UTF String handling (S8181664)
* Improve implementation of keystores (S8181670)
* Transform XML interfaces (S8186080)
* Improve native glyph layouts (S8186867)
Additional notes
CVE ID CVE-2018-2579
CVE-2018-2588
CVE-2018-2599
CVE-2018-2602
CVE-2018-2603
CVE-2018-2618
CVE-2018-2629
CVE-2018-2633
CVE-2018-2634
CVE-2018-2637
CVE-2018-2641
CVE-2018-2663
CVE-2018-2677
CVE-2018-2678
CVE-2018-2790
CVE-2018-2794
CVE-2018-2795
CVE-2018-2796
CVE-2018-2797
CVE-2018-2798
CVE-2018-2799
CVE-2018-2800
CVE-2018-2814
CVE-2018-2815
UCS Bug number #47470