Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

SUSE: 2018:2839-1 Moderate: Java 1.8.0 IBM Partial DoS Threat

suse
Calendar Grey September 24, 2018
Dist Suse Esm H88
Red Hat Security Patch resolved multiple vulnerabilities in python-3.9, enhancing protection and reliability for clients.
An update that fixes 10 vulnerabilities is now available

Summary

This update for java-1_8_0-ibm to 8.0.5.20 fixes the following security issues: - CVE-2018-2952: Vulnerability in subcomponent: Concurrency. Difficult to exploit vulnerability allowed unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded, JRockit (bsc#1104668) - CVE-2018-2940: Vulnerability in subcomponent: Libraries. Easily exploitable vulnerability allowed unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than

References

#1104668

Cross- CVE-2016-0705 CVE-2017-3732 CVE-2017-3736

CVE-2018-12539 CVE-2018-1517 CVE-2018-1656

CVE-2018-2940 CVE-2018-2952 CVE-2018-2964

CVE-2018-2973

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server for SAP 12-SP1

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP1-LTSS

SUSE Enterprise Storage 4

https://www.suse.com/security/cve/CVE-2016-0705.html

https://www.suse.com/security/cve/CVE-2017-3732.html

https://www.suse.com/security/cve/CVE-2017-3736.html

https://www.suse.com/security/cve/CVE-2018-12539.html

https://www.suse.com/security/cve/CVE-2018-1517.html

Announcement ID: SUSE-SU-2018:2839-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here