Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

SUSE: 2020:1511-2 Important: Java-11-OpenJDK Denial of Service Issues

suse
Calendar Grey July 7, 2020
Dist Suse Esm H88
SUSE Security Patch for python3 addresses 12 critical vulnerabilities affecting system stability.
An update that fixes 13 vulnerabilities is now available

Summary

This update for java-11-openjdk fixes the following issues: Java was updated to jdk-11.0.7+10 (April 2020 CPU, bsc#1169511). Security issues fixed: - CVE-2020-2754: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511). - CVE-2020-2755: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511). - CVE-2020-2756: Fixed an incorrect handling of regular expressions that could have resulted in denial of service (bsc#1169511). - CVE-2020-2757: Fixed an object deserialization issue that could have resulted in denial of service via crafted serialized input (bsc#1169511). - CVE-2020-2767: Fixed an incorrect handling of certificate messages during TLS handshakes (bsc#1169511).

References

#1167462 #1169511

Cross- CVE-2020-2754 CVE-2020-2755 CVE-2020-2756

CVE-2020-2757 CVE-2020-2767 CVE-2020-2773

CVE-2020-2778 CVE-2020-2781 CVE-2020-2800

CVE-2020-2803 CVE-2020-2805 CVE-2020-2816

CVE-2020-2830

Affected Products:

SUSE Linux Enterprise Module for Packagehub Subpackages 15-SP1

https://www.suse.com/security/cve/CVE-2020-2754.html

https://www.suse.com/security/cve/CVE-2020-2755.html

https://www.suse.com/security/cve/CVE-2020-2756.html

https://www.suse.com/security/cve/CVE-2020-2757.html

https://www.suse.com/security/cve/CVE-2020-2767.html

https://www.suse.com/security/cve/CVE-2020-2773.html

https://www.suse.com/security/cve/CVE-2020-2778.html

https://www.suse.com/security/cve/CVE-2020-2781.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:1511-2
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here