Debian Security Advisory
DSA-4268-1 openjdk-8 -- security update
- Date Reported:
- 10 Aug 2018
- Affected Packages:
- openjdk-8
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2018-2952.
- More information:
-
It was discovered that the PatternSyntaxException class in the Concurrency component of OpenJDK, an implementation of the Oracle Java platform could result in denial of service via excessive memory consumption.
For the stable distribution (stretch), this problem has been fixed in version 8u181-b13-1~deb9u1.
We recommend that you upgrade your openjdk-8 packages.
For the detailed security status of openjdk-8 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/openjdk-8