Alerts This Week
Warning Icon 1 933
Alerts This Week
Warning Icon 1 933

openSUSE 15.2: 2021:0374-1 Java Threat Fix Released with Moderate Severity

opensuse
Calendar Grey March 3, 2021
Dist Opensuse Esm H88
openSUSE upgrade addresses CVE-2020-14803 concerning java-1_8_0-openjdk. Mitigate this security risk by following the patch instructions provided.
An update that fixes one vulnerability is now available

Description

This update for java-1_8_0-openjdk fixes the following issues:

- Update to version jdk8u282 (icedtea 3.18.0)

* January 2021 CPU (bsc#1181239)

* Security fixes

+ JDK-8247619: Improve Direct Buffering of Characters (CVE-2020-14803)

* Import of OpenJDK 8 u282 build 01

+ JDK-6962725: Regtest javax/swing/JFileChooser/6738668/

/bug6738668.java fails under Linux

+ JDK-8025936: Windows .pdb and .map files does not have proper

dependencies setup

+ JDK-8030350: Enable additional compiler warnings for GCC

+ JDK-8031423: Test java/awt/dnd/DisposeFrameOnDragCrash/

/DisposeFrameOnDragTest.java fails by Timeout on Windows

+ JDK-8036122: Fix warning 'format not a string literal'

+ JDK-8051853: new URI("x/").resolve("..").getSchemeSpecificPart()

returns null!

+ JDK-8132664: closed/javax/swing/DataTransfer/DefaultNoDrop/

/DefaultNoDrop.java locks on Windows

+ JDK-8134632:...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-374=1

Package List

- openSUSE Leap 15.2 (i586 x86_64):

java-1_8_0-openjdk-1.8.0.282-lp152.2.9.1

java-1_8_0-openjdk-accessibility-1.8.0.282-lp152.2.9.1

java-1_8_0-openjdk-debuginfo-1.8.0.282-lp152.2.9.1

java-1_8_0-openjdk-debugsource-1.8.0.282-lp152.2.9.1

java-1_8_0-openjdk-demo-1.8.0.282-lp152.2.9.1

java-1_8_0-openjdk-demo-debuginfo-1.8.0.282-lp152.2.9.1

java-1_8_0-openjdk-devel-1.8.0.282-lp152.2.9.1

java-1_8_0-openjdk-devel-debuginfo-1.8.0.282-lp152.2.9.1

java-1_8_0-openjdk-headless-1.8.0.282-lp152.2.9.1

java-1_8_0-openjdk-headless-debuginfo-1.8.0.282-lp152.2.9.1

java-1_8_0-openjdk-src-1.8.0.282-lp152.2.9.1

- openSUSE Leap 15.2 (noarch):

java-1_8_0-openjdk-javadoc-1.8.0.282-lp152.2.9.1

References

https://www.suse.com/security/cve/CVE-2020-14803.html

https://bugzilla.suse.com/1181239

Announcement ID: openSUSE-SU-2021:0374-1
Rating: moderate
Affected Products: openSUSE Leap 15.2 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here