Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

openSUSE Leap 15.3: 2021:3615-1 Important Java Security Flaws

opensuse
Calendar Grey November 4, 2021
Dist Opensuse Esm H88
Essential patch for openSUSE rectifying 15 significant vulnerabilities in java-1_8_0-openj9 to bolster both system security and reliability.
An update that fixes 15 vulnerabilities is now available

Description

This update for java-1_8_0-openj9 fixes the following issues:

Update to OpenJDK 8u312 build 07 with OpenJ9 0.29.0 virtual machine

including Oracle July 2021 and October 2021 CPU changes

- CVE-2021-2161: Fixed incorrect handling of partially quoted arguments in

ProcessBuilder on Windows (bsc#1185056).

- CVE-2021-2163: Fixed incomplete enforcement of JAR signing disabled

algorithms (bsc#1185055).

- CVE-2021-2341: Fixed flaw inside the FtpClient (bsc#1188564).

- CVE-2021-2369: Fixed JAR file handling problem containing multiple

MANIFEST.MF files (bsc#1188565).

- CVE-2021-2388: Fixed flaw inside the Hotspot component performed range

check elimination (bsc#1188566).

- CVE-2021-35550: Fixed weak ciphers preferred over stronger ones for TLS

(bsc#1191901).

- CVE-2021-35556: Fixed excessive memory allocation in RTFParser

(bsc#1191910).

- CVE-2021-35559: Fixed excessive memory allocation in RTFReader

(bsc#1191911).

-...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-3615=1

Package List

- openSUSE Leap 15.3 (ppc64le s390x x86_64):

java-1_8_0-openj9-1.8.0.312-3.18.2

java-1_8_0-openj9-accessibility-1.8.0.312-3.18.2

java-1_8_0-openj9-debuginfo-1.8.0.312-3.18.2

java-1_8_0-openj9-debugsource-1.8.0.312-3.18.2

java-1_8_0-openj9-demo-1.8.0.312-3.18.2

java-1_8_0-openj9-demo-debuginfo-1.8.0.312-3.18.2

java-1_8_0-openj9-devel-1.8.0.312-3.18.2

java-1_8_0-openj9-headless-1.8.0.312-3.18.2

java-1_8_0-openj9-src-1.8.0.312-3.18.2

- openSUSE Leap 15.3 (noarch):

java-1_8_0-openj9-javadoc-1.8.0.312-3.18.2

References

https://www.suse.com/security/cve/CVE-2021-2161.html

https://www.suse.com/security/cve/CVE-2021-2163.html

https://www.suse.com/security/cve/CVE-2021-2341.html

https://www.suse.com/security/cve/CVE-2021-2369.html

https://www.suse.com/security/cve/CVE-2021-2388.html

https://www.suse.com/security/cve/CVE-2021-35550.html

https://www.suse.com/security/cve/CVE-2021-35556.html

https://www.suse.com/security/cve/CVE-2021-35559.html

https://www.suse.com/security/cve/CVE-2021-35561.html

https://www.suse.com/security/cve/CVE-2021-35564.html

https://www.suse.com/security/cve/CVE-2021-35565.html

https://www.suse.com/security/cve/CVE-2021-35567.html

https://www.suse.com/security/cve/CVE-2021-35578.html

https://www.suse.com/security/cve/CVE-2021-35586.html

https://www.suse.com/security/cve/CVE-2021-35603.html

https://bugzilla.suse.com/1185055

https://bugzilla.suse.com/1185056

https://bugzilla.suse.com/1188564

https://bugzilla.suse.com/1188565

https://bugzilla.suse.com/1188566

https://bugzilla.suse.com/1191901

https://bugz...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:3615-1
Rating: important
Affected Products: openSUSE Leap 15.3 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here