Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

openSUSE: 2013:0377-1 Critical: Java-1_7_0-Openjdk Security Update

opensuse
Calendar Grey March 1, 2013
Dist Opensuse Esm H88
Important security patch released for openSUSE, targeting several vulnerabilities linked to Java. This update includes 21 corrections, all rated as critical.
An update that fixes 21 vulnerabilities is now available.

Description

java-1_7_0-openjdk was updated to icedtea-2.3.6

(bnc#803379) containing various security and bugfixes:

* Security fixes

- S6563318, CVE-2013-0424: RMI data sanitization

- S6664509, CVE-2013-0425: Add logging context

- S6664528, CVE-2013-0426: Find log level matching its

name or value given at construction time

- S6776941: CVE-2013-0427: Improve thread pool shutdown

- S7141694, CVE-2013-0429: Improving CORBA internals

- S7173145: Improve in-memory representation of

splashscreens

- S7186945: Unpack200 improvement

- S7186946: Refine unpacker resource usage

- S7186948: Improve Swing data validation

- S7186952, CVE-2013-0432: Improve clipboard access

- S7186954: Improve connection performance

- S7186957: Improve Pack200 data validation

- S7192392, CVE-2013-0443: Better validation of client

keys

- S7192393, CVE-2013-0440: Better Checking of order of

TLS Messages

- S7192977, CVE-2013-0442: Issue in toolkit thread

-...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 12.2:

zypper in -t patch openSUSE-2013-165

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 12.2 (i586 x86_64):

java-1_7_0-openjdk-1.7.0.6-3.26.1

java-1_7_0-openjdk-debuginfo-1.7.0.6-3.26.1

java-1_7_0-openjdk-debugsource-1.7.0.6-3.26.1

java-1_7_0-openjdk-demo-1.7.0.6-3.26.1

java-1_7_0-openjdk-demo-debuginfo-1.7.0.6-3.26.1

java-1_7_0-openjdk-devel-1.7.0.6-3.26.1

java-1_7_0-openjdk-devel-debuginfo-1.7.0.6-3.26.1

java-1_7_0-openjdk-javadoc-1.7.0.6-3.26.1

java-1_7_0-openjdk-src-1.7.0.6-3.26.1

References

https://www.suse.com/security/cve/CVE-2013-0424.html

https://www.suse.com/security/cve/CVE-2013-0425.html

https://www.suse.com/security/cve/CVE-2013-0426.html

https://www.suse.com/security/cve/CVE-2013-0427.html

https://www.suse.com/security/cve/CVE-2013-0428.html

https://www.suse.com/security/cve/CVE-2013-0429.html

https://www.suse.com/security/cve/CVE-2013-0431.html

https://www.suse.com/security/cve/CVE-2013-0432.html

https://www.suse.com/security/cve/CVE-2013-0433.html

https://www.suse.com/security/cve/CVE-2013-0434.html

https://www.suse.com/security/cve/CVE-2013-0435.html

https://www.suse.com/security/cve/CVE-2013-0440.html

https://www.suse.com/security/cve/CVE-2013-0441.html

https://www.suse.com/security/cve/CVE-2013-0442.html

https://www.suse.com/security/cve/CVE-2013-0443.html

https://www.suse.com/security/cve/CVE-2013-0444.html

https://www.suse.com/security/cve/CVE-2013-0450.html

https://www.suse.com/security/cve/CVE-2013-1475.html

https://www.suse.com/security/cve/CVE-2013-1476.html

https://www....

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2013:0377-1
Rating: critical
Affected Products: openSUSE 12.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here