Alerts This Week
Warning Icon 1 666
Alerts This Week
Warning Icon 1 666

SUSE: 2015:0344-1 Critical: Java Update Improves Security on Server

suse
Calendar Grey February 21, 2015
Dist Suse Esm H88
Important SUSE upgrade addresses Java security flaws and enhances system reliability with timely fixes.
An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four fixes is now av...

Summary

java-1_7_0-ibm was updated to version 1.7.0_sr7.3 to fix 37 security issues: * CVE-2014-8891: Unspecified vulnerability (bnc#916266) * CVE-2014-8892: Unspecified vulnerability (bnc#916265) * CVE-2014-3065: Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 before SR16 FP2 (6.0.16.2), and before SR16 FP8 (5.0.16.8) allows local users to execute arbitrary code via vectors related to the shared classes cache (bnc#904889). * CVE-2014-3566: The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue (bnc#901223).

References

#891701 #901223 #901239 #904889 #916265 #916266

Cross- CVE-2014-8891 CVE-2014-8892

Affected Products:

SUSE Linux Enterprise Server 11 SP2 LTSS

https://www.suse.com/security/cve/CVE-2014-8891.html

https://www.suse.com/security/cve/CVE-2014-8892.html

https://bugzilla.suse.com/show_bug.cgi?id=891701

https://bugzilla.suse.com/show_bug.cgi?id=901223

https://bugzilla.suse.com/show_bug.cgi?id=901239

https://bugzilla.suse.com/show_bug.cgi?id=904889

https://bugzilla.suse.com/show_bug.cgi?id=916265

https://bugzilla.suse.com/show_bug.cgi?id=916266

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0344-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here