Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2015:1331-1 Important: Java 1_7_1 IBM Security Issues

suse
Calendar Grey July 31, 2015
Scroller Suse
SUSE's latest patch addresses urgent issues in java-1_8_0-oracle. Safeguard your infrastructure against these threats.
An update that fixes 20 vulnerabilities is now available

Summary

IBM Java was updated to 7.1-3.10 to fix several security issues. The following vulnerabilities were fixed: * CVE-2015-1931: IBM Java Security Components store plain text data in memory dumps, which could allow a local attacker to obtain information to aid in further attacks against the system. * CVE-2015-2590: Easily exploitable vulnerability in the Libraries component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted in unauthorized Operating System takeover including arbitrary code execution. * CVE-2015-2601: Easily exploitable vulnerability in the JCE component allowed successful unauthenticated network attacks via multiple protocols. Successful attack of this vulnerability could have resulted

References

#935540 #938895

Cross- CVE-2015-1931 CVE-2015-2590 CVE-2015-2601

CVE-2015-2613 CVE-2015-2619 CVE-2015-2621

CVE-2015-2625 CVE-2015-2632 CVE-2015-2637

CVE-2015-2638 CVE-2015-2664 CVE-2015-2808

CVE-2015-4000 CVE-2015-4729 CVE-2015-4731

CVE-2015-4732 CVE-2015-4733 CVE-2015-4748

CVE-2015-4749 CVE-2015-4760

Affected Products:

SUSE Linux Enterprise Software Development Kit 12

SUSE Linux Enterprise Server 12

https://www.suse.com/security/cve/CVE-2015-1931.html

https://www.suse.com/security/cve/CVE-2015-2590.html

https://www.suse.com/security/cve/CVE-2015-2601.html

https://www.suse.com/security/cve/CVE-2015-2613.html

https://www.suse.com/security/cve/CVE-2015-2619.html

https://www.suse.com/security/cve/CVE-2015-2621.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2015:1331-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.