Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE: 2020:1511-1 Important: Java-11-OpenJDK Denial Of Service Threat

suse
Calendar Grey May 29, 2020
Dist Suse Esm H88
SUSE announces a critical patch for java-11-openjdk addressing 13 security flaws, which includes vulnerabilities that could lead to denial of service.
An update that fixes 13 vulnerabilities is now available

Summary

This update for java-11-openjdk fixes the following issues: Java was updated to jdk-11.0.7+10 (April 2020 CPU, bsc#1169511). Security issues fixed: - CVE-2020-2754: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511). - CVE-2020-2755: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511). - CVE-2020-2756: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511). - CVE-2020-2757: Fixed an object deserialization issue that could have resulted in denial of service via crafted serialized input (bsc#1169511). - CVE-2020-2767: Fixed an incorrect handling of certificate messages during TLS handshakes (bsc#1169511).

References

#1167462 #1169511

Cross- CVE-2020-2754 CVE-2020-2755 CVE-2020-2756

CVE-2020-2757 CVE-2020-2767 CVE-2020-2773

CVE-2020-2778 CVE-2020-2781 CVE-2020-2800

CVE-2020-2803 CVE-2020-2805 CVE-2020-2816

CVE-2020-2830

Affected Products:

SUSE Linux Enterprise Server for SAP 15

SUSE Linux Enterprise Server 15-LTSS

SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP2

SUSE Linux Enterprise Module for Basesystem 15-SP2

SUSE Linux Enterprise Module for Basesystem 15-SP1

SUSE Linux Enterprise High Performance Computing 15-LTSS

SUSE Linux Enterprise High Performance Computing 15-ESPOS

https://www.suse.com/security/cve/CVE-2020-2754.html

https://www.suse.com/security/cve/CVE-2020-2755.html

https://www.suse.com/security/cve/CVE-2020-2756.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:1511-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here