Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE 12.2: 2012:1154-1 Critical: Remote Exploit in Java OpenJDK

opensuse
Calendar Grey September 12, 2012
Dist Opensuse Esm H88
The recent patch addresses various vulnerabilities in openSUSE's java-1_7_0-openjdk, greatly fortifying system defenses.
An update that fixes four vulnerabilities is now available.

Description

Java-1_7_0-openjdk was updated to fix a remote exploit

(CVE-2012-4681).

Also bugfixes were done:

- fix build on ARM and i586

- remove files that are no longer used

- zero build can be enabled using rpmbuild (osc build)

--with zero

- add hotspot 2.1 needed for zero

- fix filelist on %{ix86}

* Security fixes

- S7162476, CVE-2012-1682: XMLDecoder security issue via

ClassFinder

- S7194567, CVE-2012-3136: Improve long term persistence

of java.beans objects

- S7163201, CVE-2012-0547: Simplify toolkit internals

references

- RH852051, CVE-2012-4681, S7162473: Reintroduce

PackageAccessible checks removed in 6788531.

* OpenJDK

- Fix Zero FTBFS issues with 2.3

- S7180036: Build failure in Mac platform caused by fix #

7163201

- S7182135: Impossible to use some editors directly

- S7183701: [TEST]

closed/java/beans/security/TestClassFinder.java –

compilation failed

- S7185678:

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 12.2:

zypper in -t patch openSUSE-2012-592

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 12.2 (i586 x86_64):

java-1_7_0-openjdk-1.7.0.6-3.12.1

java-1_7_0-openjdk-debuginfo-1.7.0.6-3.12.1

java-1_7_0-openjdk-debugsource-1.7.0.6-3.12.1

java-1_7_0-openjdk-demo-1.7.0.6-3.12.1

java-1_7_0-openjdk-demo-debuginfo-1.7.0.6-3.12.1

java-1_7_0-openjdk-devel-1.7.0.6-3.12.1

java-1_7_0-openjdk-devel-debuginfo-1.7.0.6-3.12.1

java-1_7_0-openjdk-javadoc-1.7.0.6-3.12.1

java-1_7_0-openjdk-src-1.7.0.6-3.12.1

References

https://www.suse.com/security/cve/CVE-2012-0547.html

https://www.suse.com/security/cve/CVE-2012-1682.html

https://www.suse.com/security/cve/CVE-2012-3136.html

https://www.suse.com/security/cve/CVE-2012-4681.html

--

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2012:1154-1
Rating: critical
Affected Products: openSUSE 12.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here