Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE Leap 42.1: SU-2016:0270-1 Critical Access Issue for Java

opensuse
Calendar Grey January 27, 2016
Dist Opensuse Esm H88
Important patch for openSUSE correcting vulnerabilities in Java 8. Prompt measures advised for safeguarding system stability.
An update that fixes 32 vulnerabilities is now available

Description

java-1_8_0-openjdk was updated to version 7u95 to fix several security

issues. (bsc#962743)

The following vulnerabilities were fixed:

- CVE-2015-7575: Further reduce use of MD5 (SLOTH) (bsc#960996)

- CVE-2015-8126: Vulnerability in the AWT component related to

splashscreen displays

- CVE-2015-8472: Vulnerability in the AWT component, addressed by same fix

- CVE-2016-0402: Vulnerability in the Networking component related to URL

processing

- CVE-2016-0448: Vulnerability in the JMX comonent related to attribute

processing

- CVE-2016-0466: Vulnerability in the JAXP component, related to limits

- CVE-2016-0483: Vulnerability in the AWT component related to image

decoding

- CVE-2016-0494: Vulnerability in 2D component related to font actions

Includes the following fixes from the October 2015 update: (bsc#951376)

- CVE-2015-4734: A remote user can exploit a flaw in the Embedded JGSS

component to partially access data

-...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2016-106=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.1 (i586 x86_64):

java-1_8_0-openjdk-1.8.0.72-6.1

java-1_8_0-openjdk-accessibility-1.8.0.72-6.1

java-1_8_0-openjdk-debuginfo-1.8.0.72-6.1

java-1_8_0-openjdk-debugsource-1.8.0.72-6.1

java-1_8_0-openjdk-demo-1.8.0.72-6.1

java-1_8_0-openjdk-demo-debuginfo-1.8.0.72-6.1

java-1_8_0-openjdk-devel-1.8.0.72-6.1

java-1_8_0-openjdk-headless-1.8.0.72-6.1

java-1_8_0-openjdk-headless-debuginfo-1.8.0.72-6.1

java-1_8_0-openjdk-src-1.8.0.72-6.1

- openSUSE Leap 42.1 (noarch):

java-1_8_0-openjdk-javadoc-1.8.0.72-6.1

References

https://www.suse.com/security/cve/CVE-2015-4734.html

https://www.suse.com/security/cve/CVE-2015-4803.html

https://www.suse.com/security/cve/CVE-2015-4805.html

https://www.suse.com/security/cve/CVE-2015-4806.html

https://www.suse.com/security/cve/CVE-2015-4810.html

https://www.suse.com/security/cve/CVE-2015-4835.html

https://www.suse.com/security/cve/CVE-2015-4840.html

https://www.suse.com/security/cve/CVE-2015-4842.html

https://www.suse.com/security/cve/CVE-2015-4843.html

https://www.suse.com/security/cve/CVE-2015-4844.html

https://www.suse.com/security/cve/CVE-2015-4860.html

https://www.suse.com/security/cve/CVE-2015-4868.html

https://www.suse.com/security/cve/CVE-2015-4872.html

https://www.suse.com/security/cve/CVE-2015-4881.html

https://www.suse.com/security/cve/CVE-2015-4882.html

https://www.suse.com/security/cve/CVE-2015-4883.html

https://www.suse.com/security/cve/CVE-2015-4893.html

https://www.suse.com/security/cve/CVE-2015-4901.html

https://www.suse.com/security/cve/CVE-2015-4902.html

https://www....

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:0270-1
Rating: critical
Affected Products: openSUSE Leap 42.1 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here