Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

SUSE: 2020:1684-1 Important: Java-1_8_0-Ibm DoS Risk Mitigation

suse
Calendar Grey June 19, 2020
Dist Suse Esm H88
Important SUSE patch for java-1_8_0-ibm addresses 11 vulnerabilities. Implement required updates without delay.
An update that fixes 11 vulnerabilities is now available

Summary

This update for java-1_8_0-ibm fixes the following issues: java-1_8_0-ibm was updated to Java 8.0 Service Refresh 6 Fix Pack 10 (bsc#1172277,bsc#1169511,bsc#1160968) - CVE-2020-2654: Fixed an issue which could have resulted in unauthorized ability to cause a partial denial of service - CVE-2020-2754: Forwarded references to Nashorn - CVE-2020-2755: Improved Nashorn matching - CVE-2020-2756: Improved mapping of serial ENUMs - CVE-2020-2757: Less Blocking Array Queues - CVE-2020-2781: Improved TLS session handling - CVE-2020-2800: Improved Headings for HTTP Servers - CVE-2020-2803: Enhanced buffering of byte buffers - CVE-2020-2805: Enhanced typing of methods - CVE-2020-2830: Improved Scanner conversions - CVE-2019-2949: Fixed an issue which could have resulted in unauthorized access to critical data

References

#1160968 #1169511 #1171352 #1172277

Cross- CVE-2019-2949 CVE-2020-2654 CVE-2020-2754

CVE-2020-2755 CVE-2020-2756 CVE-2020-2757

CVE-2020-2781 CVE-2020-2800 CVE-2020-2803

CVE-2020-2805 CVE-2020-2830

Affected Products:

SUSE Linux Enterprise Server for SAP 15

SUSE Linux Enterprise Server 15-LTSS

SUSE Linux Enterprise Module for Legacy Software 15-SP2

SUSE Linux Enterprise Module for Legacy Software 15-SP1

https://www.suse.com/security/cve/CVE-2019-2949.html

https://www.suse.com/security/cve/CVE-2020-2654.html

https://www.suse.com/security/cve/CVE-2020-2754.html

https://www.suse.com/security/cve/CVE-2020-2755.html

https://www.suse.com/security/cve/CVE-2020-2756.html

https://www.suse.com/security/cve/CVE-2020-2757.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:1684-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here