{"id":"USN-4257-1","summary":"openjdk-8, openjdk-lts vulnerabilities","details":"It was discovered that OpenJDK incorrectly handled exceptions during\ndeserialization in BeanContextSupport. An attacker could possibly use this\nissue to cause a denial of service or other unspecified impact.\n(CVE-2020-2583)\n\nIt was discovered that OpenJDK incorrectly validated properties of SASL\nmessages included in Kerberos GSSAPI. An unauthenticated remote attacker\nwith network access via Kerberos could possibly use this issue to insert,\nmodify or obtain sensitive information. (CVE-2020-2590)\n\nIt was discovered that OpenJDK incorrectly validated URLs. An attacker\ncould possibly use this issue to insert, edit or obtain sensitive\ninformation. (CVE-2020-2593)\n\nIt was discovered that OpenJDK Security component still used MD5 algorithm.\nA remote attacker could possibly use this issue to obtain sensitive\ninformation. (CVE-2020-2601)\n\nIt was discovered that OpenJDK incorrectly handled the application of\nserialization filters. An attacker could possibly use this issue to bypass the\nintended filter during serialization. (CVE-2020-2604)\n\nBo Zhang and Long Kuan discovered that OpenJDK incorrectly handled X.509\ncertificates. An attacker could possibly use this issue to cause a denial\nof service. (CVE-2020-2654)\n\nBengt Jonsson, Juraj Somorovsky, Kostis Sagonas, Paul Fiterau Brostean and\nRobert Merget discovered that OpenJDK incorrectly handled CertificateVerify\nTLS handshake messages. A remote attacker could possibly use this issue to\ninsert, edit or obtain sensitive information. This issue only affected\nOpenJDK 11. (CVE-2020-2655)\n\nIt was discovered that OpenJDK incorrectly enforced the limit of datagram\nsockets that can be created by a code running within a Java sandbox. An\nattacker could possibly use this issue to bypass the sandbox restrictions\ncausing a denial of service. This issue only affected OpenJDK 8.\n(CVE-2020-2659)\n","modified":"2026-04-27T15:48:47.255661583Z","published":"2020-01-28T20:03:55Z","related":["UBUNTU-CVE-2020-2583","UBUNTU-CVE-2020-2590","UBUNTU-CVE-2020-2593","UBUNTU-CVE-2020-2601","UBUNTU-CVE-2020-2604","UBUNTU-CVE-2020-2654","UBUNTU-CVE-2020-2655","UBUNTU-CVE-2020-2659"],"upstream":["CVE-2020-2583","CVE-2020-2590","CVE-2020-2593","CVE-2020-2601","CVE-2020-2604","CVE-2020-2654","CVE-2020-2655","CVE-2020-2659","UBUNTU-CVE-2020-2583","UBUNTU-CVE-2020-2590","UBUNTU-CVE-2020-2593","UBUNTU-CVE-2020-2601","UBUNTU-CVE-2020-2604","UBUNTU-CVE-2020-2654","UBUNTU-CVE-2020-2655","UBUNTU-CVE-2020-2659"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-4257-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-2583"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-2590"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-2593"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-2601"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-2604"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-2654"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-2655"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2020-2659"}],"affected":[{"package":{"name":"openjdk-8","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/openjdk-8@8u242-b08-0ubuntu3~16.04?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8u242-b08-0ubuntu3~16.04"}]}],"versions":["8u66-b01-5","8u72-b05-1ubuntu1","8u72-b05-5","8u72-b05-6","8u72-b15-1","8u72-b15-2ubuntu1","8u72-b15-2ubuntu3","8u72-b15-3ubuntu1","8u77-b03-1ubuntu2","8u77-b03-3ubuntu1","8u77-b03-3ubuntu2","8u77-b03-3ubuntu3","8u91-b14-0ubuntu4~16.04.1","8u91-b14-3ubuntu1~16.04.1","8u111-b14-2ubuntu0.16.04.2","8u121-b13-0ubuntu1.16.04.2","8u131-b11-0ubuntu1.16.04.2","8u131-b11-2ubuntu1.16.04.2","8u131-b11-2ubuntu1.16.04.3","8u151-b12-0ubuntu0.16.04.2","8u162-b12-0ubuntu0.16.04.2","8u171-b11-0ubuntu0.16.04.1","8u181-b13-0ubuntu0.16.04.1","8u181-b13-1ubuntu0.16.04.1","8u191-b12-0ubuntu0.16.04.1","8u191-b12-2ubuntu0.16.04.1","8u212-b03-0ubuntu1.16.04.1","8u222-b10-1ubuntu1~16.04.1","8u232-b09-0ubuntu1~16.04.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"8u242-b08-0ubuntu3~16.04","binary_name":"openjdk-8-demo"},{"binary_version":"8u242-b08-0ubuntu3~16.04","binary_name":"openjdk-8-jdk"},{"binary_version":"8u242-b08-0ubuntu3~16.04","binary_name":"openjdk-8-jdk-headless"},{"binary_version":"8u242-b08-0ubuntu3~16.04","binary_name":"openjdk-8-jre"},{"binary_version":"8u242-b08-0ubuntu3~16.04","binary_name":"openjdk-8-jre-headless"},{"binary_version":"8u242-b08-0ubuntu3~16.04","binary_name":"openjdk-8-jre-jamvm"},{"binary_version":"8u242-b08-0ubuntu3~16.04","binary_name":"openjdk-8-jre-zero"},{"binary_version":"8u242-b08-0ubuntu3~16.04","binary_name":"openjdk-8-source"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4257-1.json","cves_map":{"ecosystem":"Ubuntu:16.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2020-2583"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2020-2590"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2020-2593"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-2601"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-2604"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2020-2654"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-2659"}]}}},{"package":{"name":"openjdk-8","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/openjdk-8@8u242-b08-0ubuntu3~18.04?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8u242-b08-0ubuntu3~18.04"}]}],"versions":["8u144-b01-2","8u151-b12-1","8u162-b12-1","8u171-b11-0ubuntu0.18.04.1","8u181-b13-0ubuntu0.18.04.1","8u181-b13-1ubuntu0.18.04.1","8u191-b12-0ubuntu0.18.04.1","8u191-b12-2ubuntu0.18.04.1","8u212-b03-0ubuntu1.18.04.1","8u222-b10-1ubuntu1~18.04.1","8u232-b09-0ubuntu1~18.04.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"8u242-b08-0ubuntu3~18.04","binary_name":"openjdk-8-demo"},{"binary_version":"8u242-b08-0ubuntu3~18.04","binary_name":"openjdk-8-jdk"},{"binary_version":"8u242-b08-0ubuntu3~18.04","binary_name":"openjdk-8-jdk-headless"},{"binary_version":"8u242-b08-0ubuntu3~18.04","binary_name":"openjdk-8-jre"},{"binary_version":"8u242-b08-0ubuntu3~18.04","binary_name":"openjdk-8-jre-headless"},{"binary_version":"8u242-b08-0ubuntu3~18.04","binary_name":"openjdk-8-jre-zero"},{"binary_version":"8u242-b08-0ubuntu3~18.04","binary_name":"openjdk-8-source"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4257-1.json","cves_map":{"ecosystem":"Ubuntu:18.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2020-2583"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2020-2590"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2020-2593"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-2601"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-2604"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2020-2654"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-2655"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-2659"}]}}},{"package":{"name":"openjdk-lts","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/openjdk-lts@11.0.6+10-1ubuntu1~18.04.1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.0.6+10-1ubuntu1~18.04.1"}]}],"versions":["9.0.4+12-2ubuntu4","9.0.4+12-4ubuntu1","10~46-4ubuntu1","10~46-5ubuntu1","10.0.1+10-1ubuntu2","10.0.1+10-3ubuntu1","10.0.2+13-1ubuntu0.18.04.1","10.0.2+13-1ubuntu0.18.04.2","10.0.2+13-1ubuntu0.18.04.3","10.0.2+13-1ubuntu0.18.04.4","11.0.2+9-3ubuntu1~18.04.3","11.0.3+7-1ubuntu2~18.04.1","11.0.4+11-1ubuntu2~18.04.3","11.0.5+10-0ubuntu1.1~18.04"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"11.0.6+10-1ubuntu1~18.04.1","binary_name":"openjdk-11-demo"},{"binary_version":"11.0.6+10-1ubuntu1~18.04.1","binary_name":"openjdk-11-jdk"},{"binary_version":"11.0.6+10-1ubuntu1~18.04.1","binary_name":"openjdk-11-jdk-headless"},{"binary_version":"11.0.6+10-1ubuntu1~18.04.1","binary_name":"openjdk-11-jre"},{"binary_version":"11.0.6+10-1ubuntu1~18.04.1","binary_name":"openjdk-11-jre-headless"},{"binary_version":"11.0.6+10-1ubuntu1~18.04.1","binary_name":"openjdk-11-jre-zero"},{"binary_version":"11.0.6+10-1ubuntu1~18.04.1","binary_name":"openjdk-11-source"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4257-1.json","cves_map":{"ecosystem":"Ubuntu:18.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2020-2583"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2020-2590"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2020-2593"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-2601"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-2604"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2020-2654"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-2655"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2020-2659"}]}}}],"schema_version":"1.7.5"}