Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE Leap 42.2: 2016:2985-1 Important: Java Security Enhancements

opensuse
Calendar Grey December 2, 2016
Dist Opensuse Esm H88
Address various problems pertaining to java-1_8_0-openjdk in openSUSE. The update brings crucial updates aimed at improving security protocols.
An update that solves 7 vulnerabilities and has one errata An update that solves 7 vulnerabilities and has one errata An update that solves 7 vulnerabilities and has one errata is ...

Description

OpenJDK Java was updated to jdk8u111 (icedtea 3.2.0) to fix the following

issues:

* Security fixes

+ S8146490: Direct indirect CRL checks

+ S8151921: Improved page resolution

+ S8155968: Update command line options

+ S8155973, CVE-2016-5542: Tighten jar checks (bsc#1005522)

+ S8156794: Extend data sharing

+ S8157176: Improved classfile parsing

+ S8157739, CVE-2016-5554: Classloader Consistency Checking

(bsc#1005523)

+ S8157749: Improve handling of DNS error replies

+ S8157753: Audio replay enhancement

+ S8157759: LCMS Transform Sampling Enhancement

+ S8157764: Better handling of interpolation plugins

+ S8158302: Handle contextual glyph substitutions

+ S8158993, CVE-2016-5568: Service Menu services (bsc#1005525)

+ S8159495: Fix index offsets

+ S8159503: Amend Annotation Actions

+ S8159511: Stack map validation

+ S8159515: Improve indy validation

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.2:

zypper in -t patch openSUSE-2016-1380=1

- openSUSE Leap 42.1:

zypper in -t patch openSUSE-2016-1380=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.2 (i586 x86_64):

java-1_8_0-openjdk-1.8.0.111-3.1

java-1_8_0-openjdk-accessibility-1.8.0.111-3.1

java-1_8_0-openjdk-debuginfo-1.8.0.111-3.1

java-1_8_0-openjdk-debugsource-1.8.0.111-3.1

java-1_8_0-openjdk-demo-1.8.0.111-3.1

java-1_8_0-openjdk-demo-debuginfo-1.8.0.111-3.1

java-1_8_0-openjdk-devel-1.8.0.111-3.1

java-1_8_0-openjdk-devel-debuginfo-1.8.0.111-3.1

java-1_8_0-openjdk-headless-1.8.0.111-3.1

java-1_8_0-openjdk-headless-debuginfo-1.8.0.111-3.1

java-1_8_0-openjdk-src-1.8.0.111-3.1

- openSUSE Leap 42.2 (noarch):

java-1_8_0-openjdk-javadoc-1.8.0.111-3.1

- openSUSE Leap 42.1 (i586 x86_64):

java-1_8_0-openjdk-1.8.0.111-18.1

java-1_8_0-openjdk-accessibility-1.8.0.111-18.1

java-1_8_0-openjdk-debuginfo-1.8.0.111-18.1

java-1_8_0-openjdk-debugsource-1.8.0.111-18.1

java-1_8_0-openjdk-demo-1.8.0.111-18.1

java-1_8_0-openjdk-demo-debuginfo-1.8.0.111-18.1

java-1_8_0-openjdk-devel-1.8.0.111-18.1

java-1_8_0-openjdk-devel-debuginfo-1.8.0.111-18.1

java-1_8_0-openjdk-headless-1.8.0.111-18.1

java-1_8_0-ope...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2016-5542.html

https://www.suse.com/security/cve/CVE-2016-5554.html

https://www.suse.com/security/cve/CVE-2016-5556.html

https://www.suse.com/security/cve/CVE-2016-5568.html

https://www.suse.com/security/cve/CVE-2016-5573.html

https://www.suse.com/security/cve/CVE-2016-5582.html

https://www.suse.com/security/cve/CVE-2016-5597.html

https://bugzilla.suse.com/1005522

https://bugzilla.suse.com/1005523

https://bugzilla.suse.com/1005524

https://bugzilla.suse.com/1005525

https://bugzilla.suse.com/1005526

https://bugzilla.suse.com/1005527

https://bugzilla.suse.com/1005528

https://bugzilla.suse.com/988651

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2016:2985-1
Rating: important
Affected Products: openSUSE Leap 42.2 openSUSE Leap 42.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here