Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2020:2453-1 Moderate: Java 1_8_0-IBM Multiple Security Issues

suse
Calendar Grey September 2, 2020
Dist Suse Esm H88
An update has been released for java-1_8_0-ibm, resolving several security vulnerabilities affecting SUSE systems.
An update that fixes 9 vulnerabilities is now available

Summary

This update for java-1_8_0-ibm fixes the following issues: - Update to Java 8.0 Service Refresh 6 Fix Pack 15 [bsc#1175259, bsc#1174157] CVE-2020-14577 CVE-2020-14578 CVE-2020-14579 CVE-2020-14581 CVE-2020-14556 CVE-2020-14621 CVE-2020-14593 CVE-2020-14583 CVE-2019-17639 * Class Libraries: - JAVA.UTIL.ZIP.DEFLATER OPERATIONS THROW JAVA.LANG.INTERNALERROR - JAVA 8 DECODER OBJECTS CONSUME A LARGE AMOUNT OF JAVA HEAP - TRANSLATION MESSAGES UPDATE FOR JCL - UPDATE TIMEZONE INFORMATION TO TZDATA2020A * Java Virtual Machine: - IBM JAVA REGISTERS A HANDLER BY DEFAULT FOR SIGABRT - LARGE MEMORY FOOTPRINT HELD BY TRACECONTEXT OBJECT * JIT Compiler: - CRASH IN THE INTERPRETER AFTER OSR FROM INLINED SYNCHRONIZED METHOD IN DEBUGGING MODE - INTERMITTENT ASSERTION FAILURE REPORTED

References

#1174157 #1175259

Cross- CVE-2019-17639 CVE-2020-14556 CVE-2020-14577

CVE-2020-14578 CVE-2020-14579 CVE-2020-14581

CVE-2020-14583 CVE-2020-14593 CVE-2020-14621

Affected Products:

SUSE Linux Enterprise Server for SAP 15

SUSE Linux Enterprise Server 15-LTSS

SUSE Linux Enterprise Module for Legacy Software 15-SP2

SUSE Linux Enterprise Module for Legacy Software 15-SP1

https://www.suse.com/security/cve/CVE-2019-17639.html

https://www.suse.com/security/cve/CVE-2020-14556.html

https://www.suse.com/security/cve/CVE-2020-14577.html

https://www.suse.com/security/cve/CVE-2020-14578.html

https://www.suse.com/security/cve/CVE-2020-14579.html

https://www.suse.com/security/cve/CVE-2020-14581.html

https://www.suse.com/security/cve/CVE-2020-14583.html

Announcement ID: SUSE-SU-2020:2453-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here