VDB
GCVE-VVD-MAGEIA-2023-272
GCVE-VVD-MAGEIA-2023-272
Advisory Published
The updated packages fix security vulnerabilities and a file conflict :
Improper connection handling during TLS handshake. (CVE-2023-21930)
Incorrect enqueue of references in garbage collector. (CVE-2023-21954)
Certificate validation issue in TLS session negotiation.
(CVE-2023-21967)
Swing HTML parsing issue. (CVE-2023-21939)
Incorrect handling of NULL characters in ProcessBuilder.
(CVE-2023-21938)
Missing string checks for NULL characters. (CVE-2023-21937)
Missing check for slash characters in URI-to-path conversion.
(CVE-2023-21968)
Array indexing integer overflow issue. (CVE-2023-22045)
Improper handling of slash characters in URI-to-path conversion.
(CVE-2023-22049)
O(n^2) growth via consecutive marks. (CVE-2023-25193)
HTTP client insufficient file name validation. (CVE-2023-22006)
ZIP file parsing infinite loop. (CVE-2023-22036)
Modulo operator array indexing issue. (CVE-2023-22044)
Weakness in AES implementation. (CVE-2023-22041)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | java-1.8.0-openjdk | 0 (affected), 1.8.0.382.b05-1.mga8 (unaffected) | — |
| Mageia | java-11-openjdk | 0 (affected), 11.0.20.0.8-1.mga8 (unaffected) | — |
| Mageia | openjfx | 0 (affected), 11.0.9.2-4.mga8 (unaffected) | — |
| Mageia | java-1.8.0-openjdk | 0 (affected), 1.8.0.382.b05-1.mga9 (unaffected) | — |
| Mageia | java-11-openjdk | 0 (affected), 11.0.20.0.8-1.mga9 (unaffected) | — |
| Mageia | java-17-openjdk | 0 (affected), 17.0.8.0.7-1.mga9 (unaffected) | — |
| Mageia | java-latest-openjdk | 0 (affected), 20.0.2.0.9-1.rolling.2.mga9 (unaffected) | — |
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.