Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

openSUSE Leap 42.1 Important: Java Security Update 2016:2052-1

opensuse
Calendar Grey August 11, 2016
Dist Opensuse Esm H88
Important openSUSE patch addresses 11 security concerns for java-1_7_0-openjdk, providing several corrections and vulnerability mitigations.
An update that solves 11 vulnerabilities and has three An update that solves 11 vulnerabilities and has three An update that solves 11 vulnerabilities and has three fixes is now av...

Description

This update for java-1_7_0-openjdk fixes the following issues:

- Update to 2.6.7 - OpenJDK 7u111

* Security fixes

- S8079718, CVE-2016-3458: IIOP Input Stream Hooking (bsc#989732)

- S8145446, CVE-2016-3485: Perfect pipe placement (Windows

only) (bsc#989734)

- S8147771: Construction of static protection domains under Javax

custom policy

- S8148872, CVE-2016-3500: Complete name checking (bsc#989730)

- S8149962, CVE-2016-3508: Better delineation of XML processing

(bsc#989731)

- S8150752: Share Class Data

- S8151925: Font reference improvements

- S8152479, CVE-2016-3550: Coded byte streams (bsc#989733)

- S8155981, CVE-2016-3606: Bolster bytecode verification (bsc#989722)

- S8155985, CVE-2016-3598: Persistent Parameter Processing (bsc#989723)

- S8158571, CVE-2016-3610: Additional method handle validation

(bsc#989725)

- CVE-2016-3511 (bsc#989727)

-...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2016-977=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.1 (i586 x86_64):

java-1_7_0-openjdk-1.7.0.111-34.1

java-1_7_0-openjdk-accessibility-1.7.0.111-34.1

java-1_7_0-openjdk-bootstrap-1.7.0.111-34.1

java-1_7_0-openjdk-bootstrap-debuginfo-1.7.0.111-34.1

java-1_7_0-openjdk-bootstrap-debugsource-1.7.0.111-34.1

java-1_7_0-openjdk-bootstrap-devel-1.7.0.111-34.1

java-1_7_0-openjdk-bootstrap-devel-debuginfo-1.7.0.111-34.1

java-1_7_0-openjdk-bootstrap-headless-1.7.0.111-34.1

java-1_7_0-openjdk-bootstrap-headless-debuginfo-1.7.0.111-34.1

java-1_7_0-openjdk-debuginfo-1.7.0.111-34.1

java-1_7_0-openjdk-debugsource-1.7.0.111-34.1

java-1_7_0-openjdk-demo-1.7.0.111-34.1

java-1_7_0-openjdk-demo-debuginfo-1.7.0.111-34.1

java-1_7_0-openjdk-devel-1.7.0.111-34.1

java-1_7_0-openjdk-devel-debuginfo-1.7.0.111-34.1

java-1_7_0-openjdk-headless-1.7.0.111-34.1

java-1_7_0-openjdk-headless-debuginfo-1.7.0.111-34.1

java-1_7_0-openjdk-src-1.7.0.111-34.1

- openSUSE Leap 42.1 (noarch):

java-1_7_0-openjdk-javadoc-1.7.0.111-34.1

References

https://www.suse.com/security/cve/CVE-2016-3458.html

https://www.suse.com/security/cve/CVE-2016-3485.html

https://www.suse.com/security/cve/CVE-2016-3498.html

https://www.suse.com/security/cve/CVE-2016-3500.html

https://www.suse.com/security/cve/CVE-2016-3503.html

https://www.suse.com/security/cve/CVE-2016-3508.html

https://www.suse.com/security/cve/CVE-2016-3511.html

https://www.suse.com/security/cve/CVE-2016-3550.html

https://www.suse.com/security/cve/CVE-2016-3598.html

https://www.suse.com/security/cve/CVE-2016-3606.html

https://www.suse.com/security/cve/CVE-2016-3610.html

https://bugzilla.suse.com/982366

https://bugzilla.suse.com/984684

https://bugzilla.suse.com/988651

https://bugzilla.suse.com/989722

https://bugzilla.suse.com/989723

https://bugzilla.suse.com/989725

https://bugzilla.suse.com/989727

https://bugzilla.suse.com/989728

https://bugzilla.suse.com/989729

https://bugzilla.suse.com/989730

https://bugzilla.suse.com/989731

https://bugzilla.suse.com/989732

https://bugzilla.suse.com/989733

https://bugz...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:2052-1
Rating: important
Affected Products: openSUSE Leap 42.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here