Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

SUSE: 2018:3064-2 Important Update for java-1_8_0-openjdk

suse
Calendar Grey October 18, 2018
Dist Suse Esm H88
SUSE has released a Security Update addressing 5 vulnerabilities in java-1_8_0-openjdk. Critical patches to counter unauthorized access and additional security concerns have been implemented.
An update that fixes 5 vulnerabilities is now available

Summary

This update for java-1_8_0-openjdk to the jdk8u181 (icedtea 3.9.0) release fixes the following issues: These security issues were fixed: - CVE-2018-2938: Difficult to exploit vulnerability allowed unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in takeover of Java SE (bsc#1101644). - CVE-2018-2940: Vulnerability in subcomponent: Libraries. Easily exploitable vulnerability allowed unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Java SE, Java SE Embedded

References

#1101644 #1101645 #1101651 #1101656 #1106812

Cross- CVE-2018-2938 CVE-2018-2940 CVE-2018-2952

CVE-2018-2973 CVE-2018-3639

Affected Products:

SUSE Linux Enterprise Server 12-SP2-BCL

https://www.suse.com/security/cve/CVE-2018-2938.html

https://www.suse.com/security/cve/CVE-2018-2940.html

https://www.suse.com/security/cve/CVE-2018-2952.html

https://www.suse.com/security/cve/CVE-2018-2973.html

https://www.suse.com/security/cve/CVE-2018-3639.html

https://bugzilla.suse.com/1101644

https://bugzilla.suse.com/1101645

https://bugzilla.suse.com/1101651

https://bugzilla.suse.com/1101656

https://bugzilla.suse.com/1106812

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:3064-2
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here