Liberica JDK21.0.7+9Security Advisory
Search Cve

CVE-2023-42950

Published: March 27, 2024Last modified: November 5, 2024

Description

A use after free issue was addressed with improved memory management. This issue is fixed in Safari 17.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2, watchOS 10.2, macOS Sonoma 14.2. Processing maliciously crafted web content may lead to arbitrary code execution.

Severity score breakdown

ParameterValue
Base score8.8
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionREQUIRED
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactHIGH
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Status

ProductReleasePackageStatus
Liberica JDK8jdk-fullFixed (8u432+7)
jre-fullFixed (8u432+7)
11jdk-fullFixed (11.0.25+11)
jre-fullFixed (11.0.25+11)
17jdk-fullFixed (17.0.13+12)
jre-fullFixed (17.0.13+12)
21jdk-fullFixed (21.0.5+11)
jre-fullFixed (21.0.5+11)
23jdk-fullFixed (23.0.1+13)
jre-fullFixed (23.0.1+13)
Liberica NIK23 (JDK 17)fullFixed (23.0.6+1)
23 (JDK 21)fullFixed (23.1.5+1)
24 (JDK 23)fullFixed (24.1.1+1)

References

Published BELL-SAs

ON THIS PAGE