RHEL 8 : java-17-openjdk (RHSA-2023:0191)

low Nessus Plugin ID 170133

Synopsis

The remote Red Hat host is missing one or more security updates for java-17-openjdk.

Description

The remote Redhat Enterprise Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the RHSA-2023:0191 advisory.

The java-17-openjdk packages provide the OpenJDK 17 Java Runtime Environment and the OpenJDK 17 Java Software Development Kit.

Security Fix(es):

* OpenJDK: handshake DoS attack against DTLS connections (JSSE, 8287411) (CVE-2023-21835)

* OpenJDK: soundbank URL remote loading (Sound, 8293742) (CVE-2023-21843)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

* In FIPS mode, the use of a SQLite database provided by NSS was assumed, which was opened in read-only mode and with no PIN expected. This prevented the use of other databases or setting a PIN on the NSS database. This update allows more control over database use using two new properties - fips.nssdb.path and fips.nssdb.pin - which can be configured permanently in the java.security file or temporarily via command- line arguments to the Java virtual machine (BZ#2147475)

* With previous Red Hat builds of OpenJDK 17, Mac key generation and import would fail due to the lack of the CKA_SIGN attribute on the key. This attribute is now added as part of the NSS FIPS configuration. (BZ#2108191)

* NSS has offered a SQLite SecMod database for some time, and this has been available in RHEL as far back as RHEL 6. With newer NSS versions removing the Berkeley DB one, this update switches the FIPS support backed by NSS to use the SQLite backend (BZ#2023536)

* [rpminspect] Disable Java bytecode checks [java-17-openjdk, rhel-8] (BZ#2109107)

* Use the NSS SQL Database in FIPS Mode [rhel-8, openjdk-17] (BZ#2147479)

Tenable has extracted the preceding description block directly from the Red Hat Enterprise Linux security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the RHEL java-17-openjdk package based on the guidance in RHSA-2023:0191.

See Also

http://www.nessus.org/u?dc28c6b6

https://access.redhat.com/security/updates/classification/#moderate

https://bugzilla.redhat.com/show_bug.cgi?id=2108191

https://bugzilla.redhat.com/show_bug.cgi?id=2109107

https://bugzilla.redhat.com/show_bug.cgi?id=2147475

https://bugzilla.redhat.com/show_bug.cgi?id=2147479

https://bugzilla.redhat.com/show_bug.cgi?id=2160421

https://bugzilla.redhat.com/show_bug.cgi?id=2160475

https://access.redhat.com/errata/RHSA-2023:0191

Plugin Details

Severity: Low

ID: 170133

File Name: redhat-RHSA-2023-0191.nasl

Version: 1.6

Type: local

Agent: unix

Published: 1/18/2023

Updated: 11/7/2024

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 1.4

Vendor

Vendor Severity: Moderate

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 1.9

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2023-21843

CVSS v3

Risk Factor: Low

Base Score: 3.7

Temporal Score: 3.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-headless-slowdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-src-fastdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-jmods-fastdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-devel-fastdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-fastdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-jmods-slowdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-static-libs-fastdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-devel-slowdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-static-libs, cpe:/o:redhat:rhel_eus:8.4, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-javadoc-zip, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-slowdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-demo-slowdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-static-libs-slowdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-src, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-src-slowdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-demo-fastdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-javadoc, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-headless, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-headless-fastdebug, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-devel, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-demo, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk, p-cpe:/a:redhat:enterprise_linux:java-17-openjdk-jmods

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 1/18/2023

Vulnerability Publication Date: 1/17/2023

Reference Information

CVE: CVE-2023-21835, CVE-2023-21843

CWE: 400, 646

IAVA: 2023-A-0042

RHSA: 2023:0191