Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

openSUSE 11.4: 2012:1424-1 Important Java OpenJDK Security Patch

opensuse
Calendar Grey October 31, 2012
Dist Opensuse Esm H88
Crucial Linux Mint Security Patch resolves 12 severe vulnerabilities in python3, improving overall protection.
An update that fixes 15 vulnerabilities is now available.

Description

java 1.6.0 openjdk / icedtea was updated to 1.11.5

(bnc#785433)

* Security fixes

- S6631398, CVE-2012-3216: FilePermission improved path

checking

- S7093490: adjust package access in rmiregistry

- S7143535, CVE-2012-5068: ScriptEngine corrected

permissions

- S7167656, CVE-2012-5077: Multiple Seeders are being

created

- S7169884, CVE-2012-5073: LogManager checks do not work

correctly for sub-types

- S7169888, CVE-2012-5075: Narrowing resource definitions

in JMX RMI connector

- S7172522, CVE-2012-5072: Improve DomainCombiner checking

- S7186286, CVE-2012-5081: TLS implementation to better

adhere to RFC

- S7189103, CVE-2012-5069: Executors needs to maintain

state

- S7189490: More improvements to DomainCombiner checking

- S7189567, CVE-2012-5085: java net obselete protocol

- S7192975, CVE-2012-5071: Conditional usage check is

wrong

- S7195194, CVE-2012-5084: Better data validation for

Swing

- S7195917,...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch openSUSE-2012-755

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

java-1_6_0-openjdk-1.6.0.0_b24.1.11.5-21.1

java-1_6_0-openjdk-debuginfo-1.6.0.0_b24.1.11.5-21.1

java-1_6_0-openjdk-debugsource-1.6.0.0_b24.1.11.5-21.1

java-1_6_0-openjdk-demo-1.6.0.0_b24.1.11.5-21.1

java-1_6_0-openjdk-demo-debuginfo-1.6.0.0_b24.1.11.5-21.1

java-1_6_0-openjdk-devel-1.6.0.0_b24.1.11.5-21.1

java-1_6_0-openjdk-devel-debuginfo-1.6.0.0_b24.1.11.5-21.1

java-1_6_0-openjdk-javadoc-1.6.0.0_b24.1.11.5-21.1

java-1_6_0-openjdk-src-1.6.0.0_b24.1.11.5-21.1

References

https://www.suse.com/security/cve/CVE-2012-3216.html

https://www.suse.com/security/cve/CVE-2012-4416.html

https://www.suse.com/security/cve/CVE-2012-5068.html

https://www.suse.com/security/cve/CVE-2012-5069.html

https://www.suse.com/security/cve/CVE-2012-5071.html

https://www.suse.com/security/cve/CVE-2012-5072.html

https://www.suse.com/security/cve/CVE-2012-5073.html

https://www.suse.com/security/cve/CVE-2012-5075.html

https://www.suse.com/security/cve/CVE-2012-5077.html

https://www.suse.com/security/cve/CVE-2012-5079.html

https://www.suse.com/security/cve/CVE-2012-5081.html

https://www.suse.com/security/cve/CVE-2012-5084.html

https://www.suse.com/security/cve/CVE-2012-5085.html

https://www.suse.com/security/cve/CVE-2012-5086.html

https://www.suse.com/security/cve/CVE-2012-5089.html

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2012:1424-1
Rating: important
Affected Products: openSUSE 11.4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here