SUSE Security Update: Security update for Java 1.5.0
______________________________________________________________________________

Announcement ID:    SUSE-SU-2013:0835-2
Rating:             important
References:         #592934 #819288 
Cross-References:   CVE-2013-0401 CVE-2013-1491 CVE-2013-1537
                    CVE-2013-1540 CVE-2013-1557 CVE-2013-1563
                    CVE-2013-1569 CVE-2013-2383 CVE-2013-2384
                    CVE-2013-2394 CVE-2013-2417 CVE-2013-2418
                    CVE-2013-2419 CVE-2013-2420 CVE-2013-2422
                    CVE-2013-2424 CVE-2013-2429 CVE-2013-2430
                    CVE-2013-2432 CVE-2013-2433 CVE-2013-2435
                    CVE-2013-2440
Affected Products:
                    SUSE Linux Enterprise Server 10 SP4
                    SUSE Linux Enterprise Java 10 SP4
                    SUSE Linux Enterprise Desktop 10 SP4
______________________________________________________________________________

   An update that fixes 22 vulnerabilities is now available.

Description:


   IBM Java 1.5.0 has been updated to SR13-FP2 which fixes
   several bugs and  security issues.

   For more details see:

   https://www.ibm.com/support/pages/java-sdk/
   

   Security Issues:

   * CVE-2013-2422
   
   * CVE-2013-1491
   
   * CVE-2013-2435
   
   * CVE-2013-2420
   
   * CVE-2013-2432
   
   * CVE-2013-1569
   
   * CVE-2013-2384
   
   * CVE-2013-2383
   
   * CVE-2013-1557
   
   * CVE-2013-1537
   
   * CVE-2013-2440
   
   * CVE-2013-2429
   
   * CVE-2013-2430
   
   * CVE-2013-1563
   
   * CVE-2013-2394
   
   * CVE-2013-0401
   
   * CVE-2013-2424
   
   * CVE-2013-2419
   
   * CVE-2013-2417
   
   * CVE-2013-2418
   
   * CVE-2013-1540
   
   * CVE-2013-2433
   



Package List:

   - SUSE Linux Enterprise Server 10 SP4 (i586 ppc s390x x86_64):

      java-1_5_0-ibm-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-devel-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-fonts-1.5.0_sr16.2-0.5.1

   - SUSE Linux Enterprise Server 10 SP4 (s390x x86_64):

      java-1_5_0-ibm-32bit-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-devel-32bit-1.5.0_sr16.2-0.5.1

   - SUSE Linux Enterprise Server 10 SP4 (i586 ppc):

      java-1_5_0-ibm-jdbc-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-plugin-1.5.0_sr16.2-0.5.1

   - SUSE Linux Enterprise Server 10 SP4 (x86_64):

      java-1_5_0-ibm-alsa-32bit-1.5.0_sr16.2-0.5.1

   - SUSE Linux Enterprise Server 10 SP4 (i586):

      java-1_5_0-ibm-alsa-1.5.0_sr16.2-0.5.1

   - SUSE Linux Enterprise Server 10 SP4 (ppc):

      java-1_5_0-ibm-64bit-1.5.0_sr16.2-0.5.1

   - SUSE Linux Enterprise Java 10 SP4 (i586 ppc s390x x86_64):

      java-1_5_0-ibm-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-devel-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-fonts-1.5.0_sr16.2-0.5.1

   - SUSE Linux Enterprise Java 10 SP4 (ppc):

      java-1_5_0-ibm-jdbc-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-plugin-1.5.0_sr16.2-0.5.1

   - SUSE Linux Enterprise Desktop 10 SP4 (i586 x86_64):

      java-1_5_0-ibm-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-demo-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-devel-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-fonts-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-src-1.5.0_sr16.2-0.5.1

   - SUSE Linux Enterprise Desktop 10 SP4 (x86_64):

      java-1_5_0-ibm-32bit-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-alsa-32bit-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-devel-32bit-1.5.0_sr16.2-0.5.1

   - SUSE Linux Enterprise Desktop 10 SP4 (i586):

      java-1_5_0-ibm-alsa-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-jdbc-1.5.0_sr16.2-0.5.1
      java-1_5_0-ibm-plugin-1.5.0_sr16.2-0.5.1


References:

   https://www.suse.com/security/cve/CVE-2013-0401.html
   https://www.suse.com/security/cve/CVE-2013-1491.html
   https://www.suse.com/security/cve/CVE-2013-1537.html
   https://www.suse.com/security/cve/CVE-2013-1540.html
   https://www.suse.com/security/cve/CVE-2013-1557.html
   https://www.suse.com/security/cve/CVE-2013-1563.html
   https://www.suse.com/security/cve/CVE-2013-1569.html
   https://www.suse.com/security/cve/CVE-2013-2383.html
   https://www.suse.com/security/cve/CVE-2013-2384.html
   https://www.suse.com/security/cve/CVE-2013-2394.html
   https://www.suse.com/security/cve/CVE-2013-2417.html
   https://www.suse.com/security/cve/CVE-2013-2418.html
   https://www.suse.com/security/cve/CVE-2013-2419.html
   https://www.suse.com/security/cve/CVE-2013-2420.html
   https://www.suse.com/security/cve/CVE-2013-2422.html
   https://www.suse.com/security/cve/CVE-2013-2424.html
   https://www.suse.com/security/cve/CVE-2013-2429.html
   https://www.suse.com/security/cve/CVE-2013-2430.html
   https://www.suse.com/security/cve/CVE-2013-2432.html
   https://www.suse.com/security/cve/CVE-2013-2433.html
   https://www.suse.com/security/cve/CVE-2013-2435.html
   https://www.suse.com/security/cve/CVE-2013-2440.html
   https://bugzilla.novell.com/592934
   https://bugzilla.novell.com/819288
   https://login.microfocus.com/nidp/app/login

SuSE: 2013:0835-2: important: Java 1.5.0

June 10, 2013
An update that fixes 22 vulnerabilities is now available

Summary

IBM Java 1.5.0 has been updated to SR13-FP2 which fixes several bugs and security issues. For more details see: https://www.ibm.com/support/pages/java-sdk/ Security Issues: * CVE-2013-2422 * CVE-2013-1491 * CVE-2013-2435 * CVE-2013-2420 * CVE-2013-2432 * CVE-2013-1569 * CVE-2013-2384 * CVE-2013-2383 * CVE-2013-1557 * CVE-2013-1537 * CVE-2013-2440 * CVE-2013-2429 * CVE-2013-2430 * CVE-2013-1563 * CVE-2013-2394 * CVE-2013-0401 * CVE-2013-2424 * CVE-2013-2419 * CVE-2013-2417 * CVE-2013-2418 * CVE-2013-1540 * CVE-2013-2433 Package List: - SUSE Linux Enterprise Server 10 SP4 (i586 ppc s390x x86_64): java-1_5_0-ibm-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-devel-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-fonts-1.5.0_sr16.2-0.5.1 - SUSE Linux Enterprise Server 10 SP4 (s390x x86_64): java-1_5_0-ibm-32bit-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-devel-32bit-1.5.0_sr16.2-0.5.1 - SUSE Linux Enterprise Server 10 SP4 (i586 ppc): java-1_5_0-ibm-jdbc-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-plugin-1.5.0_sr16.2-0.5.1 - SUSE Linux Enterprise Server 10 SP4 (x86_64): java-1_5_0-ibm-alsa-32bit-1.5.0_sr16.2-0.5.1 - SUSE Linux Enterprise Server 10 SP4 (i586): java-1_5_0-ibm-alsa-1.5.0_sr16.2-0.5.1 - SUSE Linux Enterprise Server 10 SP4 (ppc): java-1_5_0-ibm-64bit-1.5.0_sr16.2-0.5.1 - SUSE Linux Enterprise Java 10 SP4 (i586 ppc s390x x86_64): java-1_5_0-ibm-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-devel-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-fonts-1.5.0_sr16.2-0.5.1 - SUSE Linux Enterprise Java 10 SP4 (ppc): java-1_5_0-ibm-jdbc-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-plugin-1.5.0_sr16.2-0.5.1 - SUSE Linux Enterprise Desktop 10 SP4 (i586 x86_64): java-1_5_0-ibm-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-demo-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-devel-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-fonts-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-src-1.5.0_sr16.2-0.5.1 - SUSE Linux Enterprise Desktop 10 SP4 (x86_64): java-1_5_0-ibm-32bit-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-alsa-32bit-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-devel-32bit-1.5.0_sr16.2-0.5.1 - SUSE Linux Enterprise Desktop 10 SP4 (i586): java-1_5_0-ibm-alsa-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-jdbc-1.5.0_sr16.2-0.5.1 java-1_5_0-ibm-plugin-1.5.0_sr16.2-0.5.1

References

#592934 #819288

Cross- CVE-2013-0401 CVE-2013-1491 CVE-2013-1537

CVE-2013-1540 CVE-2013-1557 CVE-2013-1563

CVE-2013-1569 CVE-2013-2383 CVE-2013-2384

CVE-2013-2394 CVE-2013-2417 CVE-2013-2418

CVE-2013-2419 CVE-2013-2420 CVE-2013-2422

CVE-2013-2424 CVE-2013-2429 CVE-2013-2430

CVE-2013-2432 CVE-2013-2433 CVE-2013-2435

CVE-2013-2440

Affected Products:

SUSE Linux Enterprise Server 10 SP4

SUSE Linux Enterprise Java 10 SP4

SUSE Linux Enterprise Desktop 10 SP4

https://www.suse.com/security/cve/CVE-2013-0401.html

https://www.suse.com/security/cve/CVE-2013-1491.html

https://www.suse.com/security/cve/CVE-2013-1537.html

https://www.suse.com/security/cve/CVE-2013-1540.html

https://www.suse.com/security/cve/CVE-2013-1557.html

https://www.suse.com/security/cve/CVE-2013-1563.html

https://www.suse.com/security/cve/CVE-2013-1569.html

https://www.suse.com/security/cve/CVE-2013-2383.html

https://www.suse.com/security/cve/CVE-2013-2384.html

https://www.suse.com/security/cve/CVE-2013-2394.html

https://www.suse.com/security/cve/CVE-2013-2417.html

https://www.suse.com/security/cve/CVE-2013-2418.html

https://www.suse.com/security/cve/CVE-2013-2419.html

https://www.suse.com/security/cve/CVE-2013-2420.html

https://www.suse.com/security/cve/CVE-2013-2422.html

https://www.suse.com/security/cve/CVE-2013-2424.html

https://www.suse.com/security/cve/CVE-2013-2429.html

https://www.suse.com/security/cve/CVE-2013-2430.html

https://www.suse.com/security/cve/CVE-2013-2432.html

https://www.suse.com/security/cve/CVE-2013-2433.html

https://www.suse.com/security/cve/CVE-2013-2435.html

https://www.suse.com/security/cve/CVE-2013-2440.html

https://bugzilla.novell.com/592934

https://bugzilla.novell.com/819288

https://login.microfocus.com/nidp/app/login

Severity
Announcement ID: SUSE-SU-2013:0835-2
Rating: important

Related News