Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 464
Alerts This Week
Warning Icon 1 464

openSUSE 13.2: 2015:0190-1 Important: Java Security Update for Java 7u75

opensuse
Calendar Grey February 2, 2015
Scroller Opensuse
Investigate the latest openSUSE Security Update for java-1_7_0-openjdk addressing 13 vulnerabilities. Safeguard your system's integrity.
An update that fixes 13 vulnerabilities is now available

Description

OpenJDK was updated to 2.5.4 - OpenJDK 7u75 to fix security issues and

bugs:

* Security fixes

- S8046656: Update protocol support

- S8047125, CVE-2015-0395: (ref) More phantom object references

- S8047130: Fewer escapes from escape analysis

- S8048035, CVE-2015-0400: Ensure proper proxy protocols

- S8049253: Better GC validation

- S8050807, CVE-2015-0383: Better performing performance data handling

- S8054367, CVE-2015-0412: More references for endpoints

- S8055304, CVE-2015-0407: More boxing for DirectoryComboBoxModel

- S8055309, CVE-2015-0408: RMI needs better transportation considerations

- S8055479: TLAB stability

- S8055489, CVE-2014-6585: Better substitution formats

- S8056264, CVE-2014-6587: Multicast support improvements

- S8056276, CVE-2014-6591: Fontmanager feature improvements

- S8057555, CVE-2014-6593: Less cryptic cipher suite management

- S8058982, CVE-2014-6601: Better verification of...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:

zypper in -t patch openSUSE-2015-91

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 (i586 x86_64):

java-1_7_0-openjdk-1.7.0.75-4.1

java-1_7_0-openjdk-accessibility-1.7.0.75-4.1

java-1_7_0-openjdk-bootstrap-1.7.0.75-4.1

java-1_7_0-openjdk-bootstrap-debuginfo-1.7.0.75-4.1

java-1_7_0-openjdk-bootstrap-debugsource-1.7.0.75-4.1

java-1_7_0-openjdk-bootstrap-devel-1.7.0.75-4.1

java-1_7_0-openjdk-bootstrap-devel-debuginfo-1.7.0.75-4.1

java-1_7_0-openjdk-bootstrap-headless-1.7.0.75-4.1

java-1_7_0-openjdk-bootstrap-headless-debuginfo-1.7.0.75-4.1

java-1_7_0-openjdk-debuginfo-1.7.0.75-4.1

java-1_7_0-openjdk-debugsource-1.7.0.75-4.1

java-1_7_0-openjdk-demo-1.7.0.75-4.1

java-1_7_0-openjdk-demo-debuginfo-1.7.0.75-4.1

java-1_7_0-openjdk-devel-1.7.0.75-4.1

java-1_7_0-openjdk-devel-debuginfo-1.7.0.75-4.1

java-1_7_0-openjdk-headless-1.7.0.75-4.1

java-1_7_0-openjdk-headless-debuginfo-1.7.0.75-4.1

java-1_7_0-openjdk-src-1.7.0.75-4.1

- openSUSE 13.2 (noarch):

java-1_7_0-openjdk-javadoc-1.7.0.75-4.1

References

https://www.suse.com/security/cve/CVE-2014-3566.html

https://www.suse.com/security/cve/CVE-2014-6585.html

https://www.suse.com/security/cve/CVE-2014-6587.html

https://www.suse.com/security/cve/CVE-2014-6591.html

https://www.suse.com/security/cve/CVE-2014-6593.html

https://www.suse.com/security/cve/CVE-2014-6601.html

https://www.suse.com/security/cve/CVE-2015-0383.html

https://www.suse.com/security/cve/CVE-2015-0395.html

https://www.suse.com/security/cve/CVE-2015-0400.html

https://www.suse.com/security/cve/CVE-2015-0407.html

https://www.suse.com/security/cve/CVE-2015-0408.html

https://www.suse.com/security/cve/CVE-2015-0410.html

https://www.suse.com/security/cve/CVE-2015-0412.html

https://bugzilla.suse.com/show_bug.cgi?id=914041

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:0190-1
Rating: important
Affected Products: openSUSE 13.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.