Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2018:2649-1 Important: Java-1_7_1-IBM DoS Threat Fixed

suse
Calendar Grey September 7, 2018
Dist Suse Esm H88
A crucial Ubuntu upgrade resolves multiple Python library vulnerabilities, enhancing system reliability and safeguarding against potential threats.
An update that fixes 6 vulnerabilities is now available

Summary

This update for java-1_7_1-ibm fixes the following issues: Security issues fixed: - CVE-2018-1517: Fixed a flaw in the java.math component in IBM SDK, which may allow an attacker to inflict a denial-of-service attack with specially crafted String data. - CVE-2018-1656: Protect against path traversal attacks when extracting compressed dump files. - CVE-2018-2940: Fixed an easily exploitable vulnerability in the libraries subcomponent, which allowed unauthenticated attackers with network access via multiple protocols to compromise the Java SE, leading to unauthorized read access. - CVE-2018-2952: Fixed an easily exploitable vulnerability in the concurrency subcomponent, which allowed unauthenticated attackers with network access via multiple protocols to compromise the Java SE, leading

References

#1104668

Cross- CVE-2018-12539 CVE-2018-1517 CVE-2018-1656

CVE-2018-2940 CVE-2018-2952 CVE-2018-2973

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Linux Enterprise Server 12-LTSS

SUSE Enterprise Storage 4

https://www.suse.com/security/cve/CVE-2018-12539.html

https://www.suse.com/security/cve/CVE-2018-1517.html

https://www.suse.com/security/cve/CVE-2018-1656.html

https://www.suse.com/security/cve/CVE-2018-2940.html

https://www.suse.com/security/cve/CVE-2018-2952.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:2649-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here