java-1_7_0-ibm was updated to version 1.7.0_sr7.3 to fix 37 security issues: * CVE-2014-8891: Unspecified vulnerability (bnc#916266) * CVE-2014-8892: Unspecified vulnerability (bnc#916265) * CVE-2014-3065: Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 before SR16 FP2 (6.0.16.2), and before SR16 FP8 (5.0.16.8) allows local users to execute arbitrary code via vectors related to the shared classes cache (bnc#904889). * CVE-2014-3566: The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue (bnc#901223).
#891701 #901223 #901239 #904889 #916265 #916266
Cross- CVE-2014-8891 CVE-2014-8892
Affected Products:
SUSE Linux Enterprise Server 11 SP2 LTSS
https://www.suse.com/security/cve/CVE-2014-8891.html
https://www.suse.com/security/cve/CVE-2014-8892.html
https://bugzilla.suse.com/show_bug.cgi?id=891701
https://bugzilla.suse.com/show_bug.cgi?id=901223
https://bugzilla.suse.com/show_bug.cgi?id=901239
https://bugzilla.suse.com/show_bug.cgi?id=904889
https://bugzilla.suse.com/show_bug.cgi?id=916265
https://bugzilla.suse.com/show_bug.cgi?id=916266
https://scc.suse.com:443/patches/
Get the latest Linux and open source security news straight to your inbox.