Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

openSUSE 13.2: openSUSE-SU-2015:1905-1 Important: java-1_8_0-openjdk

opensuse
Calendar Grey November 4, 2015
Dist Opensuse Esm H88
An important patch for openSUSE resolves several vulnerabilities in java-1_8_0-openjdk, featuring crucial corrections related to privilege escalation.
An update that fixes 24 vulnerabilities is now available

Description

java-1_8_0-openjdk was updated to fix 24 security issues.

These security issues were fixed:

- CVE-2015-4734: A remote user can exploit a flaw in the Embedded JGSS

component to partially access data

- CVE-2015-4803: A remote user can exploit a flaw in the JRockit JAXP

component to cause partial denial of service conditions

- CVE-2015-4805: A remote user can exploit a flaw in the Embedded

Serialization component to gain elevated privileges

- CVE-2015-4806: A remote user can exploit a flaw in the Java SE Embedded

Libraries component to partially access and partially modify data

- CVE-2015-4835: A remote user can exploit a flaw in the Embedded CORBA

component to gain elevated privileges

- CVE-2015-4842: A remote user can exploit a flaw in the Embedded JAXP

component to partially access data

- CVE-2015-4843: A remote user can exploit a flaw in the Java SE Embedded

Libraries component to gain elevated privileges

-...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE 13.2:

zypper in -t patch openSUSE-2015-696=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE 13.2 (i586 x86_64):

java-1_8_0-openjdk-1.8.0.65-18.1

java-1_8_0-openjdk-accessibility-1.8.0.65-18.1

java-1_8_0-openjdk-debuginfo-1.8.0.65-18.1

java-1_8_0-openjdk-debugsource-1.8.0.65-18.1

java-1_8_0-openjdk-demo-1.8.0.65-18.1

java-1_8_0-openjdk-demo-debuginfo-1.8.0.65-18.1

java-1_8_0-openjdk-devel-1.8.0.65-18.1

java-1_8_0-openjdk-headless-1.8.0.65-18.1

java-1_8_0-openjdk-headless-debuginfo-1.8.0.65-18.1

java-1_8_0-openjdk-src-1.8.0.65-18.1

- openSUSE 13.2 (noarch):

java-1_8_0-openjdk-javadoc-1.8.0.65-18.1

References

https://www.suse.com/security/cve/CVE-2015-4734.html

https://www.suse.com/security/cve/CVE-2015-4803.html

https://www.suse.com/security/cve/CVE-2015-4805.html

https://www.suse.com/security/cve/CVE-2015-4806.html

https://www.suse.com/security/cve/CVE-2015-4810.html

https://www.suse.com/security/cve/CVE-2015-4835.html

https://www.suse.com/security/cve/CVE-2015-4840.html

https://www.suse.com/security/cve/CVE-2015-4842.html

https://www.suse.com/security/cve/CVE-2015-4843.html

https://www.suse.com/security/cve/CVE-2015-4844.html

https://www.suse.com/security/cve/CVE-2015-4860.html

https://www.suse.com/security/cve/CVE-2015-4868.html

https://www.suse.com/security/cve/CVE-2015-4872.html

https://www.suse.com/security/cve/CVE-2015-4881.html

https://www.suse.com/security/cve/CVE-2015-4882.html

https://www.suse.com/security/cve/CVE-2015-4883.html

https://www.suse.com/security/cve/CVE-2015-4893.html

https://www.suse.com/security/cve/CVE-2015-4901.html

https://www.suse.com/security/cve/CVE-2015-4902.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2015:1905-1
Rating: important
Affected Products: openSUSE 13.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here