Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2014:1526-1 Critical IBM Java Security Update Announcement

suse
Calendar Grey November 28, 2014
Scroller Suse
Essential SUSE security patch addresses 21 Java weaknesses, bolstering system resilience with updated solutions.
An update that fixes 21 vulnerabilities is now available

Summary

java-1_7_0-ibm has been updated to version 1.7.0_sr7.2 to fix 21 security issues. These security issues have been fixed: * Unspecified vulnerability (CVE-2014-3065). * The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue (CVE-2014-3566). * Unspecified vulnerability in Oracle Java SE 6u81, 7u67, and 8u20, and Java SE Embedded 7u60, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT (CVE-2014-6513). * Unspecified vulnerability in Oracle Java SE 7u67 and 8u20 allows remote attackers to affect confidentiality, integrity, and

References

#904889

Cross- CVE-2014-3065 CVE-2014-3566 CVE-2014-4288

CVE-2014-6456 CVE-2014-6457 CVE-2014-6458

CVE-2014-6466 CVE-2014-6476 CVE-2014-6492

CVE-2014-6493 CVE-2014-6502 CVE-2014-6503

CVE-2014-6506 CVE-2014-6511 CVE-2014-6512

CVE-2014-6513 CVE-2014-6515 CVE-2014-6527

CVE-2014-6531 CVE-2014-6532 CVE-2014-6558

Affected Products:

SUSE Linux Enterprise Software Development Kit 11 SP3

SUSE Linux Enterprise Server 11 SP3 for VMware

SUSE Linux Enterprise Server 11 SP3

https://www.suse.com/security/cve/CVE-2014-3065.html

https://www.suse.com/security/cve/CVE-2014-3566.html

https://www.suse.com/security/cve/CVE-2014-4288.html

https://www.suse.com/security/cve/CVE-2014-6456.html

https://www.suse.com/security/cve/CVE-2014-6457.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2014:1526-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.