Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

openSUSE 11.4: 2013:0312-1 Important: Java Security Update

opensuse
Calendar Grey February 19, 2013
Dist Opensuse Esm H88
Addresses 17 security flaws in openSUSE through the java-1_6_0-openjdk upgrade to version 1.12.1, improving overall security measures and system reliability.
An update that fixes 17 vulnerabilities is now available

Description

OpenJDK (java-1_6_0-openjdk) was updated to 1.12.1 to fix

bugs and security issues (bnc#801972)

* Security fixes (on top of 1.12.0)

- S6563318, CVE-2013-0424: RMI data sanitization

- S6664509, CVE-2013-0425: Add logging context

- S6664528, CVE-2013-0426: Find log level matching its

name or value given at construction time

- S6776941: CVE-2013-0427: Improve thread pool shutdown

- S7141694, CVE-2013-0429: Improving CORBA internals

- S7173145: Improve in-memory representation of

splashscreens

- S7186945: Unpack200 improvement

- S7186946: Refine unpacker resource usage

- S7186948: Improve Swing data validation

- S7186952, CVE-2013-0432: Improve clipboard access

- S7186954: Improve connection performance

- S7186957: Improve Pack200 data validation

- S7192392, CVE-2013-0443: Better validation of client

keys

- S7192393, CVE-2013-0440: Better Checking of order of

TLS Messages

- S7192977, CVE-2013-0442: Issue in toolkit...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 11.4:

zypper in -t patch 2013-27

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 11.4 (i586 x86_64):

java-1_6_0-openjdk-1.6.0.0_b27.1.12.1-25.1

java-1_6_0-openjdk-debuginfo-1.6.0.0_b27.1.12.1-25.1

java-1_6_0-openjdk-debugsource-1.6.0.0_b27.1.12.1-25.1

java-1_6_0-openjdk-demo-1.6.0.0_b27.1.12.1-25.1

java-1_6_0-openjdk-demo-debuginfo-1.6.0.0_b27.1.12.1-25.1

java-1_6_0-openjdk-devel-1.6.0.0_b27.1.12.1-25.1

java-1_6_0-openjdk-devel-debuginfo-1.6.0.0_b27.1.12.1-25.1

java-1_6_0-openjdk-javadoc-1.6.0.0_b27.1.12.1-25.1

java-1_6_0-openjdk-src-1.6.0.0_b27.1.12.1-25.1

References

https://www.suse.com/security/cve/CVE-2013-0424.html

https://www.suse.com/security/cve/CVE-2013-0425.html

https://www.suse.com/security/cve/CVE-2013-0426.html

https://www.suse.com/security/cve/CVE-2013-0427.html

https://www.suse.com/security/cve/CVE-2013-0428.html

https://www.suse.com/security/cve/CVE-2013-0429.html

https://www.suse.com/security/cve/CVE-2013-0432.html

https://www.suse.com/security/cve/CVE-2013-0433.html

https://www.suse.com/security/cve/CVE-2013-0434.html

https://www.suse.com/security/cve/CVE-2013-0435.html

https://www.suse.com/security/cve/CVE-2013-0440.html

https://www.suse.com/security/cve/CVE-2013-0441.html

https://www.suse.com/security/cve/CVE-2013-0442.html

https://www.suse.com/security/cve/CVE-2013-0443.html

https://www.suse.com/security/cve/CVE-2013-0450.html

https://www.suse.com/security/cve/CVE-2013-1475.html

https://www.suse.com/security/cve/CVE-2013-1476.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2013:0312-1
Rating: important
Affected Products: openSUSE 11.4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here