Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

SUSE: 2015:0376-1 Important Security Risks In Java-1_5_0-IBM

suse
Calendar Grey February 25, 2015
Dist Suse Esm H88
Essential patch for java-1_5_0-ibm on SUSE addresses various vulnerabilities. Ensure your safety by performing the update immediately.
An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four An update that solves two vulnerabilities and has four fixes is now av...

Summary

java-1_5_0-ibm has been updated to fix 19 security issues: * CVE-2014-8891: Unspecified vulnerability (bnc#916266). * CVE-2014-8892: Unspecified vulnerability (bnc#916265). * CVE-2014-3065: Unspecified vulnerability in IBM Java Runtime Environment (JRE) 7 R1 before SR2 (7.1.2.0), 7 before SR8 (7.0.8.0), 6 R1 before SR8 FP2 (6.1.8.2), 6 before SR16 FP2 (6.0.16.2), and before SR16 FP8 (5.0.16.8) allows local users to execute arbitrary code via vectors related to the shared classes cache (bnc#904889). * CVE-2014-3566: The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue (bnc#901223).

References

#891699 #901223 #901239 #904889 #916265 #916266

Cross- CVE-2014-8891 CVE-2014-8892

Affected Products:

SUSE Linux Enterprise Server 10 SP4 LTSS

https://www.suse.com/security/cve/CVE-2014-8891.html

https://www.suse.com/security/cve/CVE-2014-8892.html

https://bugzilla.suse.com/show_bug.cgi?id=891699

https://bugzilla.suse.com/show_bug.cgi?id=901223

https://bugzilla.suse.com/show_bug.cgi?id=901239

https://bugzilla.suse.com/show_bug.cgi?id=904889

https://bugzilla.suse.com/show_bug.cgi?id=916265

https://bugzilla.suse.com/show_bug.cgi?id=916266

https://scc.suse.com:443/patches/

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:0376-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here