-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Moderate: Migration Toolkit for Runtimes security update Advisory ID: RHSA-2023:3814-01 Product: Migration Toolkit for Runtimes Advisory URL: https://access.redhat.com/errata/RHSA-2023:3814 Issue date: 2023-06-27 CVE Names: CVE-2023-2798 CVE-2023-22899 ===================================================================== 1. Summary: An update is now available for Migration Toolkit for Runtimes. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Description: Migration Toolkit for Runtimes 1.1.1 ZIP artifacts Security Fix(es): * htmlUnit: Stack overflow crash causes Denial of Service (DoS) (CVE-2023-2798) * zip4j: does not always check the MAC when decrypting a ZIP archive (CVE-2023-22899) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 3. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 4. Bugs fixed (https://bugzilla.redhat.com/): 2185278 - CVE-2023-22899 zip4j: does not always check the MAC when decrypting a ZIP archive 2210366 - CVE-2023-2798 htmlUnit: Stack overflow crash causes Denial of Service (DoS) 5. References: https://access.redhat.com/security/cve/CVE-2023-2798 https://access.redhat.com/security/cve/CVE-2023-22899 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?product=migration.toolkit.runtimes&downloadType=distributions 6. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBZJsFtdzjgjWX9erEAQjoDQ/8DerK2ZpDQzd5Q+gZ6zP1DfEwEABT5jlD c6j89Cj0/jOfr3OCWC4pAyqNtSgfDxtNraND3HASPoewamK4fAL9aS0NC+Nq9U7s 0Iz0IHymbtJGRRnyhzn47LrTWQ2TFX0nYae22LO+6Qk6agtqZvTrSSQMNyKdkNlC dg6kuMHO8tSxjqgKe7XZERXELJeBk2MuLrPdCBPCIhTrXnmPUEYNiSUEvKrZhl2i slAclvJ6NYVmO0zkI8guTOOGh2m+RDCghxH5mYdX5eUgkwQdUHLn15nYfK/DXvt0 WJqfeUKbrSUy59FXr31HexXJ2GpB3YkMU/W8JyUIolOOa4XKhOv24FaZhsvREGjM p9qG5uH0iSIgIPNly98wwSOtwdVdPJvPCuPM60tc/w9brfZWOcT/vbR8x9J54q1a 7SqEpP2a4aESDqoiX57l/zcOL80fNpfuoi1TKYHefO1wICIIc85BwpFOl8LM2r9C JkEU9p5EuEhW2UNd1oPRwXhldXWKIdHdTt2Rwa84DkrorwcazOWhrk1CX/9ZEU2S fj/bxN7+pR9wDQSEKrAfVneXjbHEHIVXQ4W6XV1wrBHP3fWPwEpK2j8Jjn3sKzGI BwZ4RwpanaUXskhJWSrSywv+Yrm6DojrK/4bLcVCiASFuWbYRf4HVzrSq15vpnea prJQFb8bWRs= =uXt0 -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://listman.redhat.com/mailman/listinfo/rhsa-announce