Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE Linux 11-SP4 SUSE-SU-2017:3440-1 Important: Java SE Denial Of Service

suse
Calendar Grey December 27, 2017
Dist Suse Esm H88
SUSE has released a Security Update addressing 16 recognized vulnerabilities in java-1_7_1-ibm, aimed at improving overall system security and dependability.
An update that fixes 16 vulnerabilities is now available

Summary

This update for java-1_7_1-ibm fixes the following issues: * CVE-2017-10349: "Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u161, 7u151, 8u144 and 9; Java SE Embedded: 8u144; JRockit: R28.3.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit. Note: This vulnerability can be

References

#1070162

Cross- CVE-2016-10165 CVE-2016-9841 CVE-2017-10281

CVE-2017-10285 CVE-2017-10293 CVE-2017-10295

CVE-2017-10345 CVE-2017-10346 CVE-2017-10347

CVE-2017-10348 CVE-2017-10349 CVE-2017-10350

CVE-2017-10355 CVE-2017-10356 CVE-2017-10357

CVE-2017-10388

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

https://www.suse.com/security/cve/CVE-2016-10165.html

https://www.suse.com/security/cve/CVE-2016-9841.html

https://www.suse.com/security/cve/CVE-2017-10281.html

https://www.suse.com/security/cve/CVE-2017-10285.html

https://www.suse.com/security/cve/CVE-2017-10293.html

https://www.suse.com/security/cve/CVE-2017-10295.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2017:3440-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here