Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE Leap 15.0: 2018:3235-1 Moderate: Java-11-Openjdk Security Fix

opensuse
Calendar Grey October 19, 2018
Dist Opensuse Esm H88
Java-11-openjdk has released an update addressing eight vulnerabilities on openSUSE Leap 15.0. Learn the steps necessary to safeguard your setup.
An update that solves 8 vulnerabilities and has one errata is now available.

Description

This update for java-11-openjdk fixes the following issues:

Update to upstream tag jdk-11.0.1+13 (Oracle October 2018 CPU)

Security fixes:

- S8202936, CVE-2018-3183, bsc#1112148: Improve script engine support

- S8199226, CVE-2018-3169, bsc#1112146: Improve field accesses

- S8199177, CVE-2018-3149, bsc#1112144: Enhance JNDI lookups

- S8202613, CVE-2018-3180, bsc#1112147: Improve TLS connections stability

- S8208209, CVE-2018-3180, bsc#1112147: Improve TLS connection stability

again

- S8199172, CVE-2018-3150, bsc#1112145: Improve jar attribute checks

- S8200648, CVE-2018-3157, bsc#1112149: Make midi code more sound

- S8194534, CVE-2018-3136, bsc#1112142: Manifest better support

- S8208754, CVE-2018-3136, bsc#1112142: The fix for JDK-8194534 needs

updates

- S8196902, CVE-2018-3139, bsc#1112143: Better HTTP Redirection

Security-In-Depth fixes:

- S8194546: Choosier FileManagers - S8195874: Improve jar specification adherence

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-1205=1

Package List

- openSUSE Leap 15.0 (x86_64):

java-11-openjdk-11.0.1.0-lp150.2.6.1

java-11-openjdk-accessibility-11.0.1.0-lp150.2.6.1

java-11-openjdk-accessibility-debuginfo-11.0.1.0-lp150.2.6.1

java-11-openjdk-debuginfo-11.0.1.0-lp150.2.6.1

java-11-openjdk-debugsource-11.0.1.0-lp150.2.6.1

java-11-openjdk-demo-11.0.1.0-lp150.2.6.1

java-11-openjdk-devel-11.0.1.0-lp150.2.6.1

java-11-openjdk-headless-11.0.1.0-lp150.2.6.1

java-11-openjdk-jmods-11.0.1.0-lp150.2.6.1

java-11-openjdk-src-11.0.1.0-lp150.2.6.1

- openSUSE Leap 15.0 (noarch):

java-11-openjdk-javadoc-11.0.1.0-lp150.2.6.1

References

https://www.suse.com/security/cve/CVE-2018-3136.html

https://www.suse.com/security/cve/CVE-2018-3139.html

https://www.suse.com/security/cve/CVE-2018-3149.html

https://www.suse.com/security/cve/CVE-2018-3150.html

https://www.suse.com/security/cve/CVE-2018-3157.html

https://www.suse.com/security/cve/CVE-2018-3169.html

https://www.suse.com/security/cve/CVE-2018-3180.html

https://www.suse.com/security/cve/CVE-2018-3183.html

https://bugzilla.suse.com/1111162

https://bugzilla.suse.com/1112142

https://bugzilla.suse.com/1112143

https://bugzilla.suse.com/1112144

https://bugzilla.suse.com/1112145

https://bugzilla.suse.com/1112146

https://bugzilla.suse.com/1112147

https://bugzilla.suse.com/1112148

https://bugzilla.suse.com/1112149

--

Announcement ID: openSUSE-SU-2018:3235-1
Rating: moderate
Affected Products: openSUSE Leap 15.0 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here